CVE-2020-7643: Medium severity paypal adaptive payments sdk vulnerability
paypal-adaptive through 0.4.2 manipulation of JavaScript objects resulting in Prototype Pollution. The PayPal function could be tricked into adding or modifying properties of Object.prototype using a proto payload.
Other sources
paypal-adaptive through 0.4.2 manipulation of JavaScript objects resulting in Prototype Pollution. The PayPal function could be tricked into adding or modifying properties of Object.prototype using a proto payload.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-7643?
CVE-2020-7643 is classified as a high severity vulnerability due to its potential for prototype pollution.
How do I fix CVE-2020-7643?
To remediate CVE-2020-7643, upgrade the paypal-adaptive package to version 0.4.3 or later.
What software is affected by CVE-2020-7643?
CVE-2020-7643 affects versions of the paypal-adaptive package up to and including 0.4.2.
What type of vulnerability is CVE-2020-7643?
CVE-2020-7643 is a prototype pollution vulnerability that allows manipulation of JavaScript Objects.
Can CVE-2020-7643 be exploited remotely?
Yes, CVE-2020-7643 can be exploited remotely if the vulnerable paypal-adaptive package is used in a web application.