web3-utils@1.0.0-beta.12 vulnerabilities

Collection of utility functions used in web3.js.

  • latest version

    4.3.3

  • latest non vulnerable version

  • first published

    8 years ago

  • latest version published

    8 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the web3-utils package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Prototype Pollution

    web3-utils is a Collection of utility functions used in web3.js.

    Affected versions of this package are vulnerable to Prototype Pollution via the utility functions format and mergeDeep, due to insecure recursive merge. An attacker can manipulate an object's prototype, potentially leading to the alteration of the behavior of all objects inheriting from the affected prototype by passing specially crafted input to these functions.

    How to fix Prototype Pollution?

    Upgrade web3-utils to version 4.2.1 or higher.

    <4.2.1