CVE-2020-7770

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/11/2020
Last modified:
02/12/2022

Description

This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, however it does not properly check the key being set, leading to a prototype pollution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:json8_project:json8:*:*:*:*:*:*:*:* 1.0.3 (excluding)