CVE-2019-10750

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
23/08/2019
Last modified:
08/10/2019

Description

deeply is vulnerable to Prototype Pollution in versions before 3.1.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using using a _proto_ payload.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:deeply_project:deeply:*:*:*:*:*:node.js:*:* 3.1.0 (excluding)


References to Advisories, Solutions, and Tools