Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
deepobj: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Vulnerability Description
deepobj provides get, set, delete deep objects in javascript. Prior to 1.0.3, prototype pollution is possible when property paths contain __proto__/constructor/prototype. The property path must not be exposed as user input. This vulnerability is fixed in 1.0.3.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Vulnerability Type
CWE-1321
Vulnerability Title
deepobj 安全漏洞
Vulnerability Description
deepobj是ranfdev个人开发者的一个深度对象操作工具。 deepobj 1.0.3之前版本存在安全漏洞,该漏洞源于属性路径包含__proto__/constructor/prototype时可能发生原型污染。
CVSS Information
N/A
Vulnerability Type
N/A