QID 982959
QID 982959: Nodejs (npm) Security Update for total.js (GHSA-6cf8-qhqj-vjqm)
There is a prototype pollution vulnerability in the package total.js before version 3.4.7. The set function can be used to set a value into the object according to the path. However the keys of the path being set are not properly sanitized, leading to a prototype pollution vulnerability. The impact depends on the application. In some cases it is possible to achieve Denial of service (DoS), Remote Code Execution or Property Injection.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-6cf8-qhqj-vjqm for updates pertaining to this vulnerability.
Vendor References
- GHSA-6cf8-qhqj-vjqm -
github.com/advisories/GHSA-6cf8-qhqj-vjqm
CVEs related to QID 982959
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6cf8-qhqj-vjqm | total.js |
|