漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
1024bit extend-deep index.js prototype pollution
Vulnerability Description
A vulnerability was determined in 1024bit extend-deep up to 0.1.6. The impacted element is an unknown function of the file index.js. This manipulation of the argument __proto__ causes improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The code repository of the project has not been active for many years.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
CWE-1321
Vulnerability Title
extend-deep 安全漏洞
Vulnerability Description
extend-deep是杭盖个人开发者的一个深度递归合并对象的JavaScript工具库。 extend-deep 0.1.6及之前版本存在安全漏洞,该漏洞源于对文件index.js中参数__proto__的操作不当,可能导致对象原型属性被不当修改。
CVSS Information
N/A
Vulnerability Type
N/A