CVE-2020-7708
18.08.2020, 15:15
The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via the set, unSet, pushVal and pullVal functions.
Vendor | Product | Version |
---|---|---|
irrelon | \@irrelon\/path | 𝑥 < 4.7.0 |
irrelon | irrelon-path | 𝑥 < 4.7.0 |
𝑥
= Vulnerable software versions
References