QID 981835
QID 981835: Nodejs (npm) Security Update for @tsed/core (GHSA-77xq-cpvg-7xm2)
"This affects the package @tsed/core before 5.65.7. This vulnerability relates to the deepExtend function which is used as part of the utils directory. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program."
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-77xq-cpvg-7xm2 for updates pertaining to this vulnerability.
Vendor References
- GHSA-77xq-cpvg-7xm2 -
github.com/advisories/GHSA-77xq-cpvg-7xm2
CVEs related to QID 981835
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-77xq-cpvg-7xm2 | @tsed/core |
|