Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The web3-core-subscriptions is a package designed to manages web3 subscriptions. A Prototype Pollution vulnerability in the attachToObject function of web3-core-subscriptions version 1.10.4 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Web3.js 安全漏洞
Vulnerability Description
Web3.js是Web3开源的一个以太坊 JSON RPC API 和 ChainSafe Systems 维护的相关工具的 TypeScript 实现。 Web3.js 1.10.4及之前版本存在安全漏洞,该漏洞源于attachToObject函数存在原型污染,可能导致拒绝服务攻击。
CVSS Information
N/A
Vulnerability Type
N/A