CVE-2019-10798
24.02.2020, 18:15
rdf-graph-array through 0.3.0-rc6 manipulation of JavaScript objects resutling in Prototype Pollution. The rdf.Graph.prototype.add method could be tricked into adding or modifying properties of Object.prototype.Enginsight
Vendor | Product | Version |
---|---|---|
rdf-graph-array_project | rdf-graph-array | 0.3.0 |
rdf-graph-array_project | rdf-graph-array | 0.3.0:rc1 |
rdf-graph-array_project | rdf-graph-array | 0.3.0:rc6 |
𝑥
= Vulnerable software versions