Description
Dot diver is a lightweight, powerful, and dependency-free TypeScript utility library that provides types and functions to work with object paths in dot notation. In versions prior to 1.0.2 there is a Prototype Pollution vulnerability in the `setByPath` function which can leads to remote code execution (RCE). This issue has been addressed in commit `98daf567` which has been included in release 1.0.2. Users are advised to upgrade. There are no known workarounds to this vulnerability.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2942 | Dot diver is a lightweight, powerful, and dependency-free TypeScript utility library that provides types and functions to work with object paths in dot notation. In versions prior to 1.0.2 there is a Prototype Pollution vulnerability in the `setByPath` function which can leads to remote code execution (RCE). This issue has been addressed in commit `98daf567` which has been included in release 1.0.2. Users are advised to upgrade. There are no known workarounds to this vulnerability. |
Github GHSA |
GHSA-9w5f-mw3p-pj47 | Prototype Pollution(PP) vulnerability in setByPath |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-04T18:54:55.435Z
Reserved: 2023-10-13T12:00:50.439Z
Link: CVE-2023-45827
Updated: 2024-08-02T20:29:32.507Z
Status : Modified
Published: 2023-11-06T18:15:08.467
Modified: 2024-11-21T08:27:26.363
Link: CVE-2023-45827
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA