CVE-2021-23426

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/09/2021
Last modified:
09/09/2021

Description

This affects all versions of package Proto. It is possible to inject pollute the object property of an application using Proto by leveraging the merge function.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:proto_project:proto:-:*:*:*:*:node.js:*:*