QID 981934
QID 981934: Nodejs (npm) Security Update for querymen (GHSA-2cf2-2383-h4jv)
querymen prior to 2.1.4 allows modification of object properties. The parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. This could be abused for Prototype Pollution attacks.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-2cf2-2383-h4jv for updates pertaining to this vulnerability.
Vendor References
- GHSA-2cf2-2383-h4jv -
github.com/advisories/GHSA-2cf2-2383-h4jv
CVEs related to QID 981934
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2cf2-2383-h4jv | querymen |
|