CVE-2018-3750
Summary
| CVE | CVE-2018-3750 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-03 21:29:00 UTC |
| Updated | 2018-08-23 13:12:00 UTC |
| Description | The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| HackerOne |
MISC |
hackerone.com |
Exploit, Issue Tracking, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 940253 AlmaLinux Security Update for nodejs:12 (ALSA-2021:0549)
- 960803 Rocky Linux Security Update for nodejs:12 (RLSA-2021:0549)
- 981037 Nodejs (npm) Security Update for deep-extend (GHSA-hr2v-3952-633q)