Vulnerabilities > CVE-2020-28267 - Unspecified vulnerability in SET Project SET 1.0.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
Prototype pollution vulnerability in '@strikeentco/set' version 1.0.0 allows attacker to cause a denial of service and may lead to remote code execution.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- https://github.com/strikeentco/set/commit/102cc6b2e1d1e0c928ced87e75df759d5541ff60
- https://github.com/strikeentco/set/commit/102cc6b2e1d1e0c928ced87e75df759d5541ff60
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2020-28267
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2020-28267