Security Advisory

CVE-2022-25948

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-12-23 23:03:51
Last updated 2025-04-14 18:09:37
Assigner snyk
CVSS score 5.3
State PUBLISHED

Description

The package liquidjs before 10.0.0 are vulnerable to Information Exposure when ownPropertyOnly parameter is set to False, which results in leaking properties of a prototype. Workaround For versions 9.34.0 and higher, an option to disable this functionality is provided.