CVE-2024-23339
22.01.2024, 23:15
hoolock is a suite of lightweight utilities designed to maintain a small footprint when bundled. Starting in version 2.0.0 and prior to version 2.2.1, utility functions related to object paths (`get`, `set`, and `update`) did not block attempts to access or alter object prototypes. Starting in version 2.2.1, the `get`, `set` and `update` functions throw a `TypeError` when a user attempts to access or alter inherited properties.
Vendor | Product | Version |
---|---|---|
elijahharry | hoolock | 2.0.0 ≤ 𝑥 < 2.2.1 |
𝑥
= Vulnerable software versions
References