7.5

CVE-2020-28495

Exploit

Prototype Pollution

This affects the package total.js before 3.4.7. The set function can be used to set a value into the object according to the path. However the keys of the path being set are not properly sanitized, leading to a prototype pollution vulnerability. The impact depends on the application. In some cases it is possible to achieve Denial of service (DoS), Remote Code Execution or Property Injection.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TotaljsTotal.Js SwPlatformnode.js Version < 3.4.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.63% 0.881
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
report@snyk.io 7.3 3.9 3.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://docs.totaljs.com/latest/en.html%23api~FrameworkUtils~U.set
Broken Link
https://github.com/totaljs/framework/blob/master/utils.js%23L6606
Broken Link
https://github.com/totaljs/framework/blob/master/utils.js%23L6617
Broken Link
https://github.com/totaljs/framework/commit/b3f901561d66ab799a4a99279893b94cad7ae4ff
Patch
Third Party Advisory
https://snyk.io/vuln/SNYK-JS-TOTALJS-1046671
Patch
Third Party Advisory
Exploit