QID 982779
QID 982779: Nodejs (npm) Security Update for valib (GHSA-pmpr-vc5q-h3jw)
valib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspection functions provided by valib. Valib uses a built-in function (hasOwnProperty) from the unsafe user-input to examine an object. It is possible for a crafted payload to overwrite this function to manipulate the inspection results to bypass security checks.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-pmpr-vc5q-h3jw for updates pertaining to this vulnerability.
Vendor References
- GHSA-pmpr-vc5q-h3jw -
github.com/advisories/GHSA-pmpr-vc5q-h3jw
CVEs related to QID 982779
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pmpr-vc5q-h3jw | valib |
|