CVE-2019-10768
19.11.2019, 21:15
In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.
| Vendor | Product | Version |
|---|---|---|
| angularjs | angularjs | 𝑥 < 1.7.9 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References