QID 982681
QID 982681: Nodejs (npm) Security Update for backbone-query-parameters (GHSA-8qpm-5c82-rf96)
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in backbone-query-parameters 0.4.0 allows a malicious user to inject properties into Object.prototype.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-8qpm-5c82-rf96 for updates pertaining to this vulnerability.
Vendor References
- GHSA-8qpm-5c82-rf96 -
github.com/advisories/GHSA-8qpm-5c82-rf96
CVEs related to QID 982681
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8qpm-5c82-rf96 | backbone-query-parameters |
|