QID 984035
QID 984035: Nodejs (npm) Security Update for extend (GHSA-qrmc-fj45-qfc2)
Versions of `extend` prior to 3.0.2 (for 3.x) and 2.0.2 (for 2.x) are vulnerable to Prototype Pollution. The `extend()` function allows attackers to modify the prototype of Object causing the addition or modification of an existing property that will exist on all objects. ## Recommendation If you're using `extend` 3.x upgrade to 3.0.2 or later. If you're using `extend` 2.x upgrade to 2.0.2 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-qrmc-fj45-qfc2 for updates pertaining to this vulnerability.
Vendor References
- GHSA-qrmc-fj45-qfc2 -
github.com/advisories/GHSA-qrmc-fj45-qfc2
CVEs related to QID 984035
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qrmc-fj45-qfc2 | extend |
|