QID 982640
QID 982640: Nodejs (npm) Security Update for typeorm (GHSA-pf2j-9qmp-jqr2)
Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-pf2j-9qmp-jqr2 for updates pertaining to this vulnerability.
Vendor References
- GHSA-pf2j-9qmp-jqr2 -
github.com/advisories/GHSA-pf2j-9qmp-jqr2
CVEs related to QID 982640
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pf2j-9qmp-jqr2 | typeorm |
|