5.3
CVE-2019-10798
- EPSS 0.34%
- Veröffentlicht 24.02.2020 18:15:15
- Zuletzt bearbeitet 21.11.2024 04:19:56
- Quelle report@snyk.io
- CVE-Watchlists
- Unerledigt
rdf-graph-array through 0.3.0-rc6 manipulation of JavaScript objects resutling in Prototype Pollution. The rdf.Graph.prototype.add method could be tricked into adding or modifying properties of Object.prototype.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rdf-graph-array Project ≫ Rdf-graph-array Version0.3.0 Update- SwPlatformnode.js
Rdf-graph-array Project ≫ Rdf-graph-array Version0.3.0 Updaterc1 SwPlatformnode.js
Rdf-graph-array Project ≫ Rdf-graph-array Version0.3.0 Updaterc6 SwPlatformnode.js
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.564 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|