0.11.8
11 years ago
3 years ago
Known vulnerabilities in the object-path package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
object-path is a package to access deep properties using a path Affected versions of this package are vulnerable to Prototype Pollution. A prototype pollution vulnerability exists in To help with preventing this type of vulnerability in the client code, also the How to fix Prototype Pollution? Upgrade | >=0.11.0 <0.11.8 |
object-path is a package to access deep properties using a path Affected versions of this package are vulnerable to Prototype Pollution. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components used in the PoC
How to fix Prototype Pollution? Upgrade | <0.11.6 |
object-path is a package to access deep properties using a path Affected versions of this package are vulnerable to Prototype Pollution. The PoC
How to fix Prototype Pollution? Upgrade | <0.11.5 |