QID 983836
QID 983836: Nodejs (npm) Security Update for phpjs (GHSA-m428-jqc4-2p5j)
All versions of phpjs up to and including 1.3.2 are vulnerable to Prototype Pollution via parse_str. phpjs is no longer maintained and users are advised to use Locutus as a replacement (https://github.com/locutusjs/locutus)
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-m428-jqc4-2p5j for updates pertaining to this vulnerability.
Vendor References
- GHSA-m428-jqc4-2p5j -
github.com/advisories/GHSA-m428-jqc4-2p5j
CVEs related to QID 983836
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-m428-jqc4-2p5j | phpjs |
|