Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

CVE-2020-7774 @ Npm-y18n-3.2.1 #118

Open
Svetlana-github opened this issue May 16, 2022 · 0 comments
Open

CVE-2020-7774 @ Npm-y18n-3.2.1 #118

Svetlana-github opened this issue May 16, 2022 · 0 comments

Comments

@Svetlana-github
Copy link
Owner

Svetlana-github commented May 16, 2022

Vulnerable Package issue exists @ Npm-y18n-3.2.1 in branch main

This affects the package y18n before 3.2.2, 4.x before 4.0.1, 5.0.x before 5.0.5 and 6.0.0-alpha.0. PoC by po6ix: const y18n = require('y18n')(); y18n.setLocale('proto'); y18n.updateLocale({polluted: true}); console.log(polluted); // true

Namespace: Svetlana-github
Repository: test
Repository Url: https://github.com/Svetlana-github/test
CxAST-Project: Svetlana-github/test
CxAST platform scan: 8821ba41-d324-41fa-8053-d13dfc156a43
Branch: main
Application: test
Severity: HIGH
State: NOT_IGNORED
Status: RECURRENT
CWE: CWE-1321


Addition Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: LOW
Availability impact: LOW
Remediation Upgrade Recommendation: 3.2.2


References
Commit
Pull request
Issue
Issue
Advisory

# for free to join this conversation on GitHub. Already have an account? # to comment
Projects
None yet
Development

No branches or pull requests

1 participant