CVE-2020-7765
Summary
| CVE | CVE-2020-7765 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-16 12:15:00 UTC |
| Updated | 2020-12-01 17:28:00 UTC |
| Description | This affects the package @firebase/util before 0.3.4. This vulnerability relates to the deepExtend function within the DeepCopy.ts file. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Firebase/util | All | All | All | All | |
| Application | Firebase/util | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Prototype Pollution in @firebase/util | Snyk | CONFIRM | snyk.io | Exploit, Third Party Advisory |
| Prevent __proto__ pollution in util.deepExtend (#4001) · firebase/firebase-js-sdk@9cf727f · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| Prevent __proto__ pollution in util.deepExtend by Feiyang1 · Pull Request #4001 · firebase/firebase-js-sdk · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Snyk Security Team
Legacy QID Mappings
- 982580 Nodejs (npm) Security Update for @firebase/util (GHSA-fpm5-vv97-jfwg)