CVE-2020-15256
Summary
| CVE | CVE-2020-15256 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-19 22:15:00 UTC |
| Updated | 2021-11-18 16:20:00 UTC |
| Description | A prototype pollution vulnerability has been found in `object-path` <= 0.11.4 affecting the `set()` method. The vulnerability is limited to the `includeInheritedProps` mode (if version >= 0.11.0 is used), which has to be explicitly enabled by creating a new instance of `object-path` and setting the option `includeInheritedProps: true`, or by using the default `withInheritedProps` instance. The default operating mode is not affected by the vulnerability if version >= 0.11.0 is used. Any usage of `set()` in versions < 0.11.0 is vulnerable. The issue is fixed in object-path version 0.11.5 As a workaround, don't use the `includeInheritedProps: true` options or the `withInheritedProps` instance if using a version >= 0.11.0. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Object-path Project | Object-path | All | All | All | All |
| Application | Object-path Project | Object-path | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fix prototype pollution in set() · mariocasciaro/object-path@2be3354 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Prototype pollution affecting the set() method using the includeInheritedProps mode · Advisory · mariocasciaro/object-path · GitHub | CONFIRM | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.