Vulnerabilities > CVE-2020-28442 - Unspecified vulnerability in Js-Data
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn function.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- https://github.com/js-data/js-data/blob/master/src/utils.js%23L417
- https://github.com/js-data/js-data/blob/master/src/utils.js%23L417
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1050978
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1050978
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1050979
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1050979
- https://snyk.io/vuln/SNYK-JS-JSDATA-1023655
- https://snyk.io/vuln/SNYK-JS-JSDATA-1023655