Description
The package liquidjs before 10.0.0 are vulnerable to Information Exposure when ownPropertyOnly parameter is set to False, which results in leaking properties of a prototype. Workaround For versions 9.34.0 and higher, an option to disable this functionality is provided.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7496 | The package liquidjs before 10.0.0 are vulnerable to Information Exposure when ownPropertyOnly parameter is set to False, which results in leaking properties of a prototype. Workaround For versions 9.34.0 and higher, an option to disable this functionality is provided. |
Github GHSA |
GHSA-45rm-2893-5f49 | liquidjs may leak properties of a prototype |
References
History
Mon, 14 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2025-04-14T18:09:37.390Z
Reserved: 2022-02-24T00:00:00.000Z
Link: CVE-2022-25948
Updated: 2024-08-03T04:49:44.308Z
Status : Modified
Published: 2022-12-22T05:15:10.487
Modified: 2025-04-14T18:15:19.417
Link: CVE-2022-25948
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA