CVE-2020-7638

Publication date

2020-04-06 12:38:22

Family

snyk

State

PUBLISHED

Description

confinit through 0.3.0 is vulnerable to Prototype Pollution.The setDeepProperty function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.