5.3
CVE-2019-10798
- EPSS 1.07%
- Veröffentlicht 24.02.2020 18:15:15
- Zuletzt bearbeitet 21.11.2024 04:19:56
- Erkennungen
rdf-graph-array through 0.3.0-rc6 manipulation of JavaScript objects resutling in Prototype Pollution. The rdf.Graph.prototype.add method could be tricked into adding or modifying properties of Object.prototype.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rdf-graph-array Project ≫ Rdf-graph-array Version 0.3.0 Update - SwPlatform node.js
Rdf-graph-array Project ≫ Rdf-graph-array Version 0.3.0 Update rc1 SwPlatform node.js
Rdf-graph-array Project ≫ Rdf-graph-array Version 0.3.0 Update rc6 SwPlatform node.js
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.07% | 0.609 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
https://github.com/rdf-ext-archive/rdf-graph-array/blob/master/index.js#L211
https://snyk.io/vuln/SNYK-JS-RDFGRAPHARRAY-551803