Improperly Controlled Modification of Dynamically-Determined Object Attributes in utilitify
High severity
GitHub Reviewed
Published
May 7, 2021
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Mar 11, 2020
Reviewed
May 3, 2021
Published to the GitHub Advisory Database
May 7, 2021
Last updated
Jan 27, 2023
utilitify prior to 1.0.3 allows modification of object properties. The merge method could be tricked into adding or modifying properties of the Object.prototype.
References