A vulnerability classified as problematic has been found in cronvel tree-kit up to 0.6.x. This affects an unknown part. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). Upgrading to version 0.7.0 is able to address this issue. The name of the patch is a63f559c50d70e8cb2eaae670dec25d1dbc4afcd. It is recommended to upgrade the affected component. The identifier VDB-216765 was assigned to this vulnerability.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7692 | A vulnerability classified as problematic has been found in cronvel tree-kit up to 0.6.x. This affects an unknown part. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). Upgrading to version 0.7.0 is able to address this issue. The name of the patch is a63f559c50d70e8cb2eaae670dec25d1dbc4afcd. It is recommended to upgrade the affected component. The identifier VDB-216765 was assigned to this vulnerability. |
Github GHSA |
GHSA-mw4x-g2x8-qcvf | tree-kit vulnerable to Prototype Pollution |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-08-03T17:23:09.835Z
Reserved: 2022-12-25T15:52:09.943Z
Link: CVE-2021-4278
No data.
Status : Modified
Published: 2022-12-25T16:15:10.400
Modified: 2024-11-21T06:37:18.093
Link: CVE-2021-4278
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA