QID 980157

QID 980157: Nodejs (npm) Security Update for set-value (GHSA-4jqc-8m5r-9rpr)

This affects the package set-value before 4.0.1. A type confusion vulnerability can lead to a bypass of CVE-2019-10747 when the user-provided keys used in the path parameter are arrays.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to GHSA-4jqc-8m5r-9rpr for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980157

    Software Advisories
    Advisory ID Software Component Link
    GHSA-4jqc-8m5r-9rpr set-value URL Logo github.com/advisories/GHSA-4jqc-8m5r-9rpr