First published: Mon Mar 09 2020(Updated: )
vega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could be tricked into adding or modifying properties of the Object.prototype.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Vega Project Vega | <1.13.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10806 is a vulnerability in vega-util prior to version 1.13.1 that allows manipulation of the object prototype.
CVE-2019-10806 affects vega-util versions prior to 1.13.1 by allowing the 'vega.mergeConfig' method to be tricked into adding or modifying properties of the Object.prototype.
CVE-2019-10806 has a severity keyword of 'medium' and a severity value of 4.3.
To fix CVE-2019-10806, upgrade vega-util to version 1.13.1 or later.
You can find more information about CVE-2019-10806 at the following references: - [GitHub Commit](https://github.com/vega/vega/commit/8f33a0b5170d7de4f12fc248ec0901234342367b) - [Snyk Vulnerability Report](https://snyk.io/vuln/SNYK-JS-VEGAUTIL-559223)