CVE-2019-10768

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/11/2019
Last modified:
07/11/2023

Description

In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:angularjs:angular.js:*:*:*:*:*:*:*:* 1.7.9 (excluding)