Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
deep-object-diff 1.1.0 - Prototype Pollution
Vulnerability Description
deep-object-diff version 1.1.0 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the '__proto__' property to be edited.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
deep-object-diff 安全漏洞
Vulnerability Description
deep-object-diff是Matt Phillips个人开发者的一个可以深度区分两个 JavaScript 对象的小型库,包括数组和对象的嵌套结构。 deep-object-diff 1.1.0版本存在安全漏洞,该漏洞源于应用程序无法正确验证传入的JSON键。
CVSS Information
N/A
Vulnerability Type
N/A