QID 982580
QID 982580: Nodejs (npm) Security Update for @firebase/util (GHSA-fpm5-vv97-jfwg)
This affects the package @firebase/util before 0.3.4. This vulnerability relates to the deepExtend function within the DeepCopy.ts file. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-fpm5-vv97-jfwg for updates pertaining to this vulnerability.
Vendor References
- GHSA-fpm5-vv97-jfwg -
github.com/advisories/GHSA-fpm5-vv97-jfwg
CVEs related to QID 982580
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fpm5-vv97-jfwg | @firebase/util |
|