QID 981892
QID 981892: Nodejs (npm) Security Update for sds (GHSA-cxm3-284p-qc4v)
Affected versions of `sds` are vulnerable to prototype pollution. The `set` function does not restrict the modification of an Object's prototype, which may allow an attacker to add or modify an existing property that will exist on all objects.
## Recommendation
Upgrade to version 4.0.0 or later
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-cxm3-284p-qc4v for updates pertaining to this vulnerability.
Vendor References
- GHSA-cxm3-284p-qc4v -
github.com/advisories/GHSA-cxm3-284p-qc4v
CVEs related to QID 981892
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cxm3-284p-qc4v | sds |
|