QID 981384
QID 981384: Nodejs (npm) Security Update for jszip (GHSA-jg8v-48h5-wgxg)
This affects the package jszip before 3.7.0. Crafting a new zip file with filenames set to Object prototype values (e.g __proto__, toString, etc) results in a returned object with a modified prototype instance.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-jg8v-48h5-wgxg for updates pertaining to this vulnerability.
Vendor References
- GHSA-jg8v-48h5-wgxg -
github.com/advisories/GHSA-jg8v-48h5-wgxg
CVEs related to QID 981384
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jg8v-48h5-wgxg | jszip |
|