QID 980388
QID 980388: Nodejs (npm) Security Update for expand-hash (GHSA-x3wr-v4wx-5qpc)
Prototype pollution vulnerability in expand-hash versions 0.1.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-x3wr-v4wx-5qpc for updates pertaining to this vulnerability.
Vendor References
- GHSA-x3wr-v4wx-5qpc -
github.com/advisories/GHSA-x3wr-v4wx-5qpc
CVEs related to QID 980388
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-x3wr-v4wx-5qpc | expand-hash |
|