CVE-2019-10798

EUVD-2021-0855
rdf-graph-array through 0.3.0-rc6 manipulation of JavaScript objects resutling in Prototype Pollution. The rdf.Graph.prototype.add method could be tricked into adding or modifying properties of Object.prototype.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
Affected Products (NVD)
VendorProductVersion
rdf-graph-array_projectrdf-graph-array
0.3.0
rdf-graph-array_projectrdf-graph-array
0.3.0:rc1
rdf-graph-array_projectrdf-graph-array
0.3.0:rc6
𝑥
= Vulnerable software versions