QID 982057
QID 982057: Nodejs (npm) Security Update for mixme (GHSA-79jw-6wg7-r9g4)
Security update has been released for mixme to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
In Node.js mixme v0.5.0, an attacker can add or alter properties of an object via 'proto' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at risk causing a potential denial of service (DoS).
Solution
The problem is corrected starting with version 0.5.1.
Vendor References
- GHSA-79jw-6wg7-r9g4 -
github.com/advisories/GHSA-79jw-6wg7-r9g4
CVEs related to QID 982057
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-79jw-6wg7-r9g4 | mixme |
|