Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS02NTN2LXJxeDktajg1cM4AAvtM

deep-object-diff vulnerable to Prototype Pollution

deep-object-diff before version 1.1.6 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the __proto__ property to be edited. This issue was fixed in version 1.1.9.

Permalink: https://github.com/advisories/GHSA-653v-rqx9-j85p
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02NTN2LXJxeDktajg1cM4AAvtM
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 1 year ago
Updated: over 1 year ago


CVSS Score: 5.3
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Identifiers: GHSA-653v-rqx9-j85p, CVE-2022-41713
References: Repository: https://github.com/mattphillips/deep-object-diff
Blast Radius: 25.0

Affected Packages

npm:deep-object-diff
Dependent packages: 425
Dependent repositories: 51,874
Downloads: 9,864,619 last month
Affected Version Ranges: >= 1.1.6, < 1.1.9
Fixed in: 1.1.9
All affected versions: 1.1.6, 1.1.7, 1.1.8
All unaffected versions: 0.0.1, 0.0.2, 0.0.3, 0.0.4, 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.1.0, 1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.1.5, 1.1.9