QID 980065
QID 980065: Nodejs (npm) Security Update for object-path (GHSA-cwx2-736x-mf6w)
Security update has been released for object-path to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
A prototype pollution vulnerability has been found in `object-path` <= 0.11.4 affecting the `set()` method. The vulnerability is limited to the `includeInheritedProps` mode (if version >= 0.11.0 is used), which has to be explicitly enabled by creating a new instance of `object-path` and setting the option `includeInheritedProps: true`, or by using the default `withInheritedProps` instance. The default operating mode is not affected by the vulnerability if version >= 0.11.0 is used. Any usage of `set()` in versions < 0.11.0 is vulnerable.
Don't use the `includeInheritedProps: true` options or the `withInheritedProps` instance if using a version >= 0.11.0.
- GHSA-cwx2-736x-mf6w -
github.com/advisories/GHSA-cwx2-736x-mf6w
CVEs related to QID 980065
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cwx2-736x-mf6w | object-path |
|