Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

CVE-2020-7774 @ Npm-y18n-3.2.1 #152

Open
CMaheshBL opened this issue May 6, 2022 · 0 comments
Open

CVE-2020-7774 @ Npm-y18n-3.2.1 #152

CMaheshBL opened this issue May 6, 2022 · 0 comments

Comments

@CMaheshBL
Copy link
Owner

CMaheshBL commented May 6, 2022

Vulnerable Package issue exists @ Npm-y18n-3.2.1 in branch master

This affects the package y18n before 3.2.2, 4.x before 4.0.1, 5.0.x before 5.0.5 and 6.0.0-alpha.0. PoC by po6ix: const y18n = require('y18n')(); y18n.setLocale('proto'); y18n.updateLocale({polluted: true}); console.log(polluted); // true

Namespace: CMaheshBL
Repository: NodeGoat
Repository Url: https://github.com/CMaheshBL/NodeGoat
CxAST-Project: CMaheshBL/NodeGoat
CxAST platform scan: d7c1c0af-6b2d-455e-8753-a6b87dbf733d
Branch: master
Application: NodeGoat
Severity: HIGH
State: NOT_IGNORED
Status: RECURRENT
CWE: CWE-1321


Addition Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: LOW
Availability impact: LOW
Remediation Upgrade Recommendation: 3.2.2


References
Commit
Pull request
Issue
Issue
Advisory

# for free to join this conversation on GitHub. Already have an account? # to comment
Projects
None yet
Development

No branches or pull requests

1 participant