Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTc3eHEtY3B2Zy03eG0y

Prototype pollution in @tsed/core

This affects the package @tsed/core before 5.65.7. This vulnerability relates to the deepExtend function which is used as part of the utils directory. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.

Permalink: https://github.com/advisories/GHSA-77xq-cpvg-7xm2
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTc3eHEtY3B2Zy03eG0y
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 3 years ago
Updated: 8 months ago


CVSS Score: 5.6
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Identifiers: GHSA-77xq-cpvg-7xm2, CVE-2020-7748
References: Repository: https://github.com/TypedProject/tsed
Blast Radius: 14.3

Affected Packages

npm:@tsed/core
Dependent packages: 92
Dependent repositories: 351
Downloads: 66,882 last month
Affected Version Ranges: < 5.65.7
Fixed in: 5.65.7
All affected versions: 3.10.2, 4.0.0, 4.0.1, 4.0.4, 4.0.5, 4.0.6, 4.0.7, 4.1.0, 4.2.0, 4.3.0, 4.4.0, 4.4.1, 4.4.2, 4.5.0, 4.5.1, 4.5.2, 4.5.3, 4.5.4, 4.6.0, 4.7.0, 4.7.1, 4.7.2, 4.8.0, 4.8.1, 4.9.0, 4.9.1, 4.10.0, 4.10.1, 4.10.2, 4.10.3, 4.10.4, 4.10.5, 4.11.0, 4.12.0, 4.12.1, 4.12.2, 4.12.3, 4.12.4, 4.13.0, 4.13.1, 4.13.2, 4.13.3, 4.13.4, 4.13.5, 4.13.6, 4.13.7, 4.13.8, 4.14.0, 4.14.1, 4.14.2, 4.14.3, 4.14.4, 4.15.0, 4.15.1, 4.15.2, 4.16.0, 4.17.0, 4.17.1, 4.17.2, 4.17.3, 4.17.4, 4.17.5, 4.17.6, 4.17.7, 4.18.0, 4.19.0, 4.19.1, 4.20.0, 4.20.1, 4.20.2, 4.20.3, 4.21.0, 4.22.0, 4.22.1, 4.23.0, 4.23.1, 4.23.2, 4.24.0, 4.25.0, 4.26.0, 4.26.1, 4.26.2, 4.26.3, 4.26.4, 4.27.0, 4.27.1, 4.27.2, 4.27.3, 4.28.0, 4.29.0, 4.29.1, 4.30.0, 4.30.1, 4.30.2, 4.30.3, 4.30.4, 4.30.5, 4.30.6, 4.31.0, 4.31.1, 4.31.2, 4.31.3, 4.31.4, 4.31.5, 4.31.6, 4.31.7, 4.31.8, 4.31.9, 4.31.10, 4.31.11, 4.31.12, 4.31.13, 4.32.0, 4.32.1, 4.32.2, 4.32.3, 4.32.4, 4.33.0, 4.33.1, 4.34.0, 4.34.1, 4.34.2, 4.34.3, 4.34.4, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.0.5, 5.0.6, 5.0.7, 5.0.8, 5.0.9, 5.1.0, 5.1.1, 5.1.2, 5.1.3, 5.2.0, 5.2.1, 5.2.2, 5.2.3, 5.2.4, 5.2.5, 5.3.0, 5.4.0, 5.5.0, 5.6.0, 5.6.1, 5.7.0, 5.7.1, 5.8.0, 5.9.0, 5.10.0, 5.11.0, 5.12.0, 5.12.1, 5.13.0, 5.14.0, 5.14.1, 5.15.0, 5.16.0, 5.17.0, 5.17.1, 5.18.0, 5.18.1, 5.18.2, 5.19.0, 5.19.1, 5.20.0, 5.20.1, 5.21.0, 5.21.1, 5.22.0, 5.23.0, 5.24.0, 5.24.1, 5.24.2, 5.25.0, 5.25.1, 5.26.0, 5.27.0, 5.27.1, 5.27.2, 5.27.3, 5.27.4, 5.27.5, 5.28.0, 5.28.1, 5.28.2, 5.28.3, 5.29.0, 5.30.0, 5.31.0, 5.31.1, 5.31.2, 5.31.3, 5.31.4, 5.32.0, 5.32.1, 5.32.2, 5.33.0, 5.33.2, 5.33.3, 5.33.4, 5.33.5, 5.34.0, 5.34.1, 5.34.2, 5.34.3, 5.34.4, 5.34.5, 5.34.6, 5.34.7, 5.34.8, 5.34.9, 5.34.10, 5.35.0, 5.35.1, 5.35.2, 5.35.3, 5.36.0, 5.36.1, 5.36.2, 5.37.0, 5.37.1, 5.38.0, 5.38.1, 5.38.2, 5.38.3, 5.38.4, 5.38.5, 5.38.6, 5.38.7, 5.39.0, 5.39.1, 5.39.2, 5.39.3, 5.40.0, 5.40.1, 5.41.0, 5.41.1, 5.41.2, 5.42.0, 5.42.1, 5.42.2, 5.42.3, 5.43.0, 5.43.1, 5.44.0, 5.44.1, 5.44.2, 5.44.3, 5.44.4, 5.44.5, 5.44.6, 5.44.7, 5.44.8, 5.44.9, 5.44.10, 5.44.11, 5.44.12, 5.44.13, 5.44.14, 5.44.15, 5.44.16, 5.44.17, 5.45.0, 5.45.1, 5.45.2, 5.45.3, 5.45.4, 5.46.0, 5.47.0, 5.47.1, 5.48.0, 5.49.0, 5.49.1, 5.49.2, 5.50.0, 5.51.0, 5.52.0, 5.52.1, 5.52.2, 5.52.3, 5.53.0, 5.53.1, 5.54.0, 5.54.1, 5.54.2, 5.54.3, 5.54.4, 5.54.5, 5.54.6, 5.55.0, 5.56.0, 5.57.0, 5.57.1, 5.57.2, 5.57.3, 5.57.4, 5.57.5, 5.57.6, 5.57.7, 5.58.0, 5.58.1, 5.58.2, 5.59.0, 5.59.1, 5.59.2, 5.59.3, 5.59.4, 5.60.0, 5.60.1, 5.60.2, 5.60.3, 5.60.4, 5.60.5, 5.60.6, 5.60.7, 5.61.0, 5.61.1, 5.61.3, 5.61.4, 5.62.0, 5.62.1, 5.62.2, 5.62.3, 5.62.4, 5.62.5, 5.62.6, 5.63.0, 5.63.1, 5.64.0, 5.64.1, 5.64.2, 5.65.0, 5.65.1, 5.65.2, 5.65.3, 5.65.4, 5.65.5, 5.65.6
All unaffected versions: 5.65.7, 5.65.8, 5.65.9, 5.65.10, 5.66.0, 5.67.0, 5.67.2, 6.0.0, 6.0.1, 6.0.2, 6.1.0, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.2.0, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.4.0, 6.4.1, 6.4.2, 6.5.0, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.7.0, 6.7.1, 6.8.0, 6.8.1, 6.9.0, 6.10.0, 6.10.1, 6.10.2, 6.10.3, 6.10.4, 6.11.0, 6.11.1, 6.11.2, 6.11.3, 6.11.4, 6.11.5, 6.12.0, 6.12.1, 6.13.0, 6.13.1, 6.14.0, 6.14.1, 6.14.2, 6.14.3, 6.14.4, 6.15.0, 6.16.0, 6.16.1, 6.17.0, 6.17.1, 6.17.2, 6.17.3, 6.17.4, 6.17.5, 6.17.6, 6.18.0, 6.18.1, 6.18.2, 6.18.3, 6.19.0, 6.19.1, 6.19.2, 6.20.0, 6.20.1, 6.21.0, 6.22.0, 6.22.1, 6.22.2, 6.22.3, 6.22.4, 6.22.5, 6.23.0, 6.23.1, 6.23.2, 6.23.3, 6.23.4, 6.24.0, 6.24.1, 6.24.2, 6.25.0, 6.25.1, 6.25.2, 6.26.0, 6.26.1, 6.26.2, 6.26.3, 6.26.4, 6.27.0, 6.28.0, 6.28.1, 6.29.0, 6.30.0, 6.30.1, 6.31.0, 6.31.1, 6.31.2, 6.32.0, 6.32.1, 6.32.2, 6.33.0, 6.33.1, 6.33.2, 6.33.3, 6.34.0, 6.34.1, 6.34.2, 6.34.3, 6.35.0, 6.35.1, 6.36.0, 6.37.0, 6.37.1, 6.37.2, 6.38.0, 6.38.1, 6.38.2, 6.38.3, 6.38.4, 6.38.5, 6.39.0, 6.39.1, 6.39.2, 6.40.0, 6.41.0, 6.41.1, 6.41.2, 6.42.0, 6.43.0, 6.43.1, 6.43.2, 6.43.3, 6.43.4, 6.44.0, 6.45.0, 6.45.1, 6.46.0, 6.46.1, 6.47.0, 6.47.1, 6.47.2, 6.47.3, 6.47.4, 6.47.5, 6.47.6, 6.48.0, 6.48.1, 6.48.2, 6.48.3, 6.48.4, 6.48.5, 6.48.6, 6.49.0, 6.49.1, 6.49.2, 6.49.3, 6.50.0, 6.51.0, 6.52.0, 6.53.0, 6.54.0, 6.55.0, 6.55.1, 6.55.2, 6.55.3, 6.55.4, 6.56.0, 6.56.1, 6.56.2, 6.57.0, 6.58.0, 6.58.1, 6.58.2, 6.59.0, 6.59.1, 6.59.2, 6.59.3, 6.59.4, 6.59.5, 6.59.6, 6.59.7, 6.59.8, 6.59.9, 6.60.0, 6.60.1, 6.60.2, 6.61.0, 6.61.1, 6.62.0, 6.62.1, 6.62.2, 6.62.3, 6.62.4, 6.63.0, 6.63.1, 6.63.2, 6.64.0, 6.64.1, 6.64.2, 6.64.3, 6.65.0, 6.66.0, 6.67.0, 6.68.0, 6.68.1, 6.68.2, 6.68.3, 6.69.0, 6.69.1, 6.69.2, 6.69.3, 6.70.0, 6.70.1, 6.70.2, 6.71.0, 6.71.1, 6.72.0, 6.72.1, 6.72.2, 6.72.3, 6.73.0, 6.73.1, 6.73.2, 6.73.3, 6.73.4, 6.73.5, 6.73.6, 6.73.7, 6.73.8, 6.73.9, 6.74.0, 6.74.1, 6.75.0, 6.75.1, 6.75.2, 6.75.3, 6.75.4, 6.75.5, 6.75.6, 6.75.7, 6.75.8, 6.75.9, 6.75.10, 6.75.11, 6.75.12, 6.76.0, 6.77.0, 6.77.1, 6.78.0, 6.78.1, 6.79.0, 6.79.1, 6.80.0, 6.80.1, 6.81.0, 6.82.0, 6.83.0, 6.84.0, 6.84.1, 6.85.0, 6.86.0, 6.86.1, 6.86.2, 6.87.0, 6.87.1, 6.87.2, 6.88.0, 6.88.1, 6.89.0, 6.90.0, 6.91.0, 6.92.0, 6.92.1, 6.93.0, 6.94.0, 6.95.0, 6.95.1, 6.95.2, 6.95.3, 6.95.4, 6.95.5, 6.95.6, 6.95.7, 6.95.8, 6.95.9, 6.95.10, 6.96.0, 6.96.1, 6.96.2, 6.97.0, 6.97.1, 6.97.2, 6.98.0, 6.98.1, 6.98.2, 6.98.3, 6.98.4, 6.98.5, 6.99.0, 6.100.0, 6.100.1, 6.100.2, 6.100.3, 6.101.0, 6.102.0, 6.102.1, 6.102.2, 6.102.3, 6.102.4, 6.102.5, 6.102.6, 6.102.7, 6.102.8, 6.103.0, 6.103.1, 6.103.2, 6.103.3, 6.104.0, 6.105.0, 6.105.1, 6.105.2, 6.105.3, 6.105.4, 6.106.0, 6.107.0, 6.107.1, 6.107.2, 6.107.3, 6.107.4, 6.107.5, 6.108.0, 6.109.0, 6.110.0, 6.110.1, 6.110.2, 6.111.0, 6.112.0, 6.113.0, 6.113.1, 6.113.2, 6.113.3, 6.114.0, 6.114.1, 6.114.2, 6.114.3, 6.114.4, 6.114.5, 6.114.6, 6.114.7, 6.114.8, 6.114.9, 6.114.10, 6.114.11, 6.114.12, 6.114.13, 6.114.14, 6.114.15, 6.114.16, 6.114.17, 6.114.18, 6.115.0, 6.115.1, 6.116.0, 6.116.1, 6.116.2, 6.116.3, 6.116.4, 6.116.5, 6.116.6, 6.117.0, 6.117.1, 6.117.2, 6.118.0, 6.119.0, 6.119.1, 6.120.0, 6.121.0, 6.121.1, 6.122.0, 6.122.1, 6.122.2, 6.122.3, 6.123.0, 6.123.1, 6.124.0, 6.125.0, 6.125.1, 6.125.2, 6.125.3, 6.126.0, 6.126.1, 6.127.0, 6.128.0, 6.128.1, 6.128.2, 6.128.3, 6.128.4, 6.128.5, 6.128.6, 6.128.7, 6.128.8, 6.128.9, 6.128.10, 6.129.0, 6.130.0, 6.131.0, 6.131.1, 6.132.0, 6.132.1, 6.133.0, 6.133.1, 7.0.0, 7.0.1, 7.0.2, 7.1.0, 7.1.1, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.4.2, 7.4.3, 7.5.0, 7.5.1, 7.5.2, 7.5.3, 7.6.0, 7.7.0, 7.7.1, 7.8.0, 7.8.1, 7.8.2, 7.8.3, 7.9.0, 7.10.0, 7.10.1, 7.11.0, 7.12.0, 7.13.0, 7.13.1, 7.13.2, 7.13.3, 7.13.4, 7.13.5, 7.13.6, 7.13.7, 7.14.0, 7.14.1, 7.14.2, 7.15.0, 7.15.1, 7.16.0, 7.16.1, 7.16.2, 7.17.0, 7.18.0, 7.18.1, 7.18.2, 7.18.3, 7.18.4, 7.19.0, 7.20.0, 7.21.0, 7.21.1, 7.22.0, 7.22.1, 7.22.2, 7.23.0, 7.23.1, 7.24.0, 7.24.1, 7.25.0, 7.26.0, 7.26.1, 7.26.2, 7.26.3, 7.27.0, 7.27.1, 7.27.2, 7.28.0, 7.29.0, 7.29.1, 7.30.0, 7.30.1, 7.30.2, 7.30.3, 7.31.0, 7.32.0, 7.33.0, 7.33.1, 7.33.2, 7.33.3, 7.33.4, 7.34.0, 7.34.1, 7.34.2, 7.34.3, 7.34.4, 7.34.5, 7.34.6, 7.34.7, 7.34.8, 7.34.9, 7.35.0, 7.35.1, 7.36.0, 7.36.1, 7.36.2, 7.36.3, 7.36.5, 7.36.6, 7.36.7, 7.36.8, 7.37.0, 7.38.0, 7.38.1, 7.39.0, 7.39.1, 7.40.0, 7.41.0, 7.41.1, 7.41.2, 7.42.0, 7.43.0, 7.43.1, 7.43.2, 7.44.0, 7.44.1, 7.45.0, 7.46.0, 7.47.0, 7.47.1, 7.48.0, 7.49.0, 7.50.0, 7.51.0, 7.51.1, 7.51.2, 7.52.0, 7.53.0, 7.54.0, 7.55.0, 7.56.0, 7.57.0, 7.57.1, 7.58.0, 7.59.0, 7.59.1, 7.60.0, 7.60.1, 7.61.0, 7.61.1, 7.61.2, 7.62.0, 7.62.1, 7.62.2, 7.62.3, 7.63.0, 7.63.1, 7.63.2, 7.63.3, 7.64.0, 7.65.0, 7.66.0, 7.67.0, 7.67.1, 7.67.2, 7.67.3, 7.67.4, 7.67.5, 7.67.6, 7.67.7, 7.67.8, 7.68.0, 7.68.1, 7.68.2, 7.68.3, 7.68.4, 7.68.5, 7.68.6, 7.69.0, 7.69.1, 7.69.2, 7.69.3, 7.69.4