First published: Tue Oct 13 2020(Updated: )
The package mathjs before 7.5.1 are vulnerable to Prototype Pollution via the deepExtend function that runs upon configuration updates.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Math.js | <7.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7743 has a medium severity due to its potential for Prototype Pollution.
To mitigate CVE-2020-7743, update the mathjs package to version 7.5.1 or higher.
Prototype Pollution in CVE-2020-7743 allows an attacker to modify an application's prototype properties which can lead to critical security issues.
CVE-2020-7743 affects all versions of mathjs prior to 7.5.1.
CVE-2020-7743 can allow unauthorized access or code execution by manipulating the JavaScript prototype chain, compromising application security.