The package set-in before 2.0.3 are vulnerable to Prototype Pollution via the setIn method, as it allows an attacker to merge object prototypes into it. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-28273](https://security.snyk.io/vuln/SNYK-JS-SETIN-1048049)
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published: 2022-03-17T11:20:56.621019Z

Updated: 2024-09-16T17:14:02.822Z

Reserved: 2022-02-24T00:00:00

Link: CVE-2022-25354

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-03-17T12:15:08.243

Modified: 2022-03-24T02:48:42.640

Link: CVE-2022-25354

cve-icon Redhat

No data.