CVE-2022-25862
Published on: Not Yet Published
Last Modified on: 05/13/2022 09:15:00 PM UTC
The following vulnerability was found:
This affects the package sds from 0.0.0. The library could be tricked into adding or modifying properties of the Object.prototype by abusing the set function located in js/set.js. **Note:** This vulnerability derives from an incomplete fix to [CVE-2020-7618](https://security.snyk.io/vuln/SNYK-JS-SDS-564123)
- CVE-2022-25862 has been assigned by
[email protected] to track the vulnerability
CVE References
Description | Tags ⓘ | Link |
---|---|---|
sds/set.js at master · monsterkodi/sds · GitHub | github.com text/html |
![]() |
Prototype Pollution in sds | CVE-2022-25862 | Snyk | snyk.io text/html |
![]() |
There are currently no QIDs associated with this CVE
There are no known software configurations (CPEs) currently associated with this CVE
Discovery Credit
P.Adithya Srinivas
Masudul Hasan Masud Bhuiyan
Cristian-Alexandru Staicu
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-25862 : This affects the package sds from 0.0.0. The library could be tricked into adding or modifying pr… twitter.com/i/web/status/1… | 2022-05-13 20:15:40 |
![]() |
CVE-2022-25862 | 2022-05-13 21:38:47 |