js-object-utilities is vulnerable to Prototype Pollution
85
High Risk
Affected versions of this package are vulnerable to prototype pollution through the lib.set function. By crafting a payload that leverages Object.prototype setters, an attacker can introduce or manipulate properties on the global prototype chain. Depending on how the library is used in the application, this may lead to denial of service or allow the execution of arbitrary commands within the application context.
You are affected if you are using a version that falls within the vulnerable range.
js-object-utilities is vulnerable to Prototype Pollution in versions 1.0.0 - 2.2.0.
Upgrade the js-object-utilities library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant