CVE-2020-7608
16.03.2020, 20:15
yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload.
| Vendor | Product | Version |
|---|---|---|
| yargs | yargs-parser | 𝑥 < 5.0.1 |
| yargs | yargs-parser | 6.0.0 ≤ 𝑥 < 13.1.2 |
| yargs | yargs-parser | 14.0.0 ≤ 𝑥 < 15.0.1 |
| yargs | yargs-parser | 16.0.0 ≤ 𝑥 < 18.1.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases