CVE-2019-10806

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/03/2020
Last modified:
02/12/2022

Description

vega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could be tricked into adding or modifying properties of the Object.prototype.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vega_project:vega:*:*:*:*:*:*:*:* 1.13.1 (excluding)