First published: Thu Jun 07 2018(Updated: )
mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
mixin-deep | <1.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of mixin-deep node module is CVE-2018-3719.
CVE-2018-3719 has a severity of 8.8 (high).
Mixin-deep node module before version 1.3.1 is affected by CVE-2018-3719.
CVE-2018-3719 allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
To fix CVE-2018-3719, upgrade mixin-deep node module to version 1.3.1 or later.