First published: Fri Feb 01 2019(Updated: )
A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary properties onto Object.prototype.
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mpath Project Mpath | <0.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-16490.
The severity of CVE-2018-16490 is high with a severity value of 7.5.
An attacker can exploit this vulnerability by providing certain input to `mpath`, allowing them to add or modify properties of the `Object` prototype, which will be present on all objects.
The recommended action is to update to version `0.5.1` or later of `mpath`.
You can find more information about CVE-2018-16490 on the following references: [Link 1](https://nvd.nist.gov/vuln/detail/CVE-2018-16490), [Link 2](https://hackerone.com/reports/390860), [Link 3](https://github.com/advisories/GHSA-h466-j336-74wx).