CVE-2020-8125
Summary
| CVE | CVE-2020-8125 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-04 20:15:00 UTC |
| Updated | 2020-02-06 18:48:00 UTC |
| Description | Flaw in input validation in npm package klona version 1.1.0 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using klona. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Klona Project |
Klona |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| HackerOne |
MISC |
hackerone.com |
Exploit, Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982758 Nodejs (npm) Security Update for klona (GHSA-8f89-2fwj-5v5r)