set-value Project set-value 0.1.2 for Node.js

CPE Details

set-value Project set-value 0.1.2 for Node.js
0.1.2
2019-09-13
14h28 +00:00
2019-09-13
14h28 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:set-value_project:set-value:0.1.2:*:*:*:*:node.js:*:*

Informations

Vendor

set-value_project

Product

set-value

Version

0.1.2

Target Software

node.js

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-23440 2021-09-12 12h55 +00:00 This affects the package set-value before <2.0.1, >=3.0.0 <4.0.1. A type confusion vulnerability can lead to a bypass of CVE-2019-10747 when the user-provided keys used in the path parameter are arrays.
9.8
Critical
CVE-2019-10747 2019-08-23 14h46 +00:00 set-value is vulnerable to Prototype Pollution in versions lower than 3.0.1. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using any of the constructor, prototype and _proto_ payloads.
9.8
Critical