QID 981851
QID 981851: Nodejs (npm) Security Update for node-forge (GHSA-92xj-mqp7-vmcj)
The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-92xj-mqp7-vmcj for updates pertaining to this vulnerability.
Vendor References
- GHSA-92xj-mqp7-vmcj -
github.com/advisories/GHSA-92xj-mqp7-vmcj
CVEs related to QID 981851
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-92xj-mqp7-vmcj | node-forge |
|