QID 980260
QID 980260: Nodejs (npm) Security Update for x-assign (GHSA-4mvj-rq4v-2fxw)
This affects all versions of package x-assign. The global proto object can be polluted using the __proto__ object.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-4mvj-rq4v-2fxw for updates pertaining to this vulnerability.
Vendor References
- GHSA-4mvj-rq4v-2fxw -
github.com/advisories/GHSA-4mvj-rq4v-2fxw
CVEs related to QID 980260
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4mvj-rq4v-2fxw | x-assign |
|