Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1wNWc5LXJqY2YtOTV2as4AAvs_

fastest-json-copy vulnerable to Prototype Pollution

fastest-json-copy version 1.0.1 allows an external attacker to edit or add new properties to an object. This is possible because the application does not correctly validate the incoming JSON keys, thus allowing the __proto__ property to be edited.

Permalink: https://github.com/advisories/GHSA-p5g9-rjcf-95vj
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wNWc5LXJqY2YtOTV2as4AAvs_
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 2 years ago
Updated: almost 2 years ago


CVSS Score: 5.3
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

EPSS Percentage: 0.00087
EPSS Percentile: 0.37513

Identifiers: GHSA-p5g9-rjcf-95vj, CVE-2022-41714
References: Repository: https://github.com/streamich/fastest-json-copy
Blast Radius: 9.2

Affected Packages

npm:fastest-json-copy
Dependent packages: 8
Dependent repositories: 54
Downloads: 10,196 last month
Affected Version Ranges: <= 1.0.1
No known fixed version
All affected versions: 1.0.0, 1.0.1