Improperly Controlled Modification of Dynamically-Determined Object Attributes in vega-util
Moderate severity
GitHub Reviewed
Published
May 7, 2021
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Mar 9, 2020
Reviewed
Apr 23, 2021
Published to the GitHub Advisory Database
May 7, 2021
Last updated
Jan 27, 2023
vega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could be tricked into adding or modifying properties of the Object.prototype.
References