First published: Tue Mar 23 2021(Updated: )
The package copy-props before 2.0.5 are vulnerable to Prototype Pollution via the main functionality.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Gulpjs Copy-props | <2.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28503 is a vulnerability that affects the package copy-props before version 2.0.5.
CVE-2020-28503 has a severity rating of 9.8 (critical).
CVE-2020-28503 allows for Prototype Pollution via the main functionality of the copy-props package.
The copy-props package versions before 2.0.5 are affected by CVE-2020-28503.
Yes, updating the copy-props package to version 2.0.5 or later will fix CVE-2020-28503.