Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2024-08-04T09:56:28.268Z

Reserved: 2020-01-28T00:00:00

Link: CVE-2020-8268

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-11-09T15:15:13.523

Modified: 2024-11-21T05:38:37.387

Link: CVE-2020-8268

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.