First published: Tue Dec 15 2020(Updated: )
All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn function.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
npm/js-data | <3.0.10 | 3.0.10 |
Math.js |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28442 is classified as a moderate vulnerability due to its potential for Prototype Pollution.
To fix CVE-2020-28442, upgrade the js-data package to version 3.0.10 or later.
Prototype Pollution in CVE-2020-28442 allows attackers to manipulate an application's prototype chain, potentially leading to arbitrary code execution.
All versions of js-data prior to 3.0.10 are affected by CVE-2020-28442.
Yes, CVE-2020-28442 can potentially be exploited remotely if the affected application accepts untrusted input.