CVE-2020-7639: Medium severity Dot Project Dot Node.js vulnerability
Published Apr 6, 2020
·Updated
eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a 'proto' payload.
Affected Software
1 affected component
Dot Project Dot Node.js<1.0.3
Remediation
Event History
Apr 6, 2020
CVE Published
via MITRE·12:48 PM
Data Sourced
via MITRE·12:48 PM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for eivindfjeldstad-dot below 1.0.3?
The vulnerability ID for eivindfjeldstad-dot below 1.0.3 is CVE-2020-7639.
2
What is the severity of CVE-2020-7639?
The severity of CVE-2020-7639 is medium with a CVSS score of 5.3.
3
What is the affected software?
eivindfjeldstad-dot below 1.0.3 with Node.js is affected by the vulnerability.
4
What is the vulnerability description?
eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution, allowing modification of 'Object.prototype'.
5
How can I fix CVE-2020-7639?
To fix CVE-2020-7639, update eivindfjeldstad-dot to version 1.0.3 or above.