Filtered by vendor Dset Project
Subscriptions
Filtered by product Dset
Subscriptions
Total
3 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2022-25645 | 2 Dset Project, Redhat | 2 Dset, Acm | 2024-09-17 | 6.5 Medium |
All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if the top-level path contains __proto__, constructor or protorype. By crafting a malicious object, it is possible to bypass this check and achieve prototype pollution. | ||||
CVE-2024-21529 | 1 Dset Project | 1 Dset | 2024-09-11 | 8.2 High |
Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user input sanitization. This vulnerability allows the attacker to inject malicious object property using the built-in Object property __proto__, which is recursively assigned to all the objects in the program. | ||||
CVE-2020-28277 | 1 Dset Project | 1 Dset | 2024-08-04 | 9.8 Critical |
Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service and may lead to remote code execution. |
Page 1 of 1.