CVE-2020-7608

CVSS v3.1 5.3 (Medium)
53% Progress
CVSS v2.0 4.6 (Medium)
46% Progress
EPSS 0.04 % (14th)
0.04% Progress
Affected Products 1
Advisories 8

yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload.

Weaknesses
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE Status
PUBLISHED
CNA
Snyk
Published Date
2020-03-16 20:15:12
(4 years ago)
Updated Date
2022-11-15 16:40:49
(22 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Yargs-parser for Node.js prior 5.0.1 version cpe:2.3:a:yargs:yargs-parser::*:*:*:*:node.js < 5.0.1
  Yargs-parser for Node.js from 6.0.0 version and prior 13.1.2 version cpe:2.3:a:yargs:yargs-parser::*:*:*:*:node.js >= 6.0.0 < 13.1.2
  Yargs-parser for Node.js from 14.0.0 version and prior 15.0.1 version cpe:2.3:a:yargs:yargs-parser::*:*:*:*:node.js >= 14.0.0 < 15.0.1
  Yargs-parser for Node.js from 16.0.0 version and prior 18.1.1 version cpe:2.3:a:yargs:yargs-parser::*:*:*:*:node.js >= 16.0.0 < 18.1.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...