QID 983161
QID 983161: Nodejs (npm) Security Update for mpath (GHSA-h466-j336-74wx)
Versions of `mpath` before 0.5.1 are vulnerable to prototype pollution. Provided certain input `mpath` can add or modify properties of the `Object` prototype. These properties will be present on all objects.
## Recommendation
Update to version `0.5.1` or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-h466-j336-74wx for updates pertaining to this vulnerability.
Vendor References
- GHSA-h466-j336-74wx -
github.com/advisories/GHSA-h466-j336-74wx
CVEs related to QID 983161
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h466-j336-74wx | mpath |
|