[NPM:GHSA-FWR7-V2MV-HH25] Prototype Pollution in async

Severity High
Affected Packages 2
Fixed Packages 2
CVEs 1

A vulnerability exists in Async through 3.2.1 for 3.x and through 2.6.3 for 2.x (fixed in 3.2.2 and 2.6.4), which could let a malicious user obtain privileges via the mapValues() method.

Package Affected Version
pkg:npm/async >= 2.0.0, < 2.6.4
pkg:npm/async >= 3.0.0, < 3.2.2
Package Fixed Version
pkg:npm/async = 2.6.4
pkg:npm/async = 3.2.2
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:npm/async async >= 2.0.0 < 2.6.4
Fixed pkg:npm/async async = 2.6.4
Affected pkg:npm/async async >= 3.0.0 < 3.2.2
Fixed pkg:npm/async async = 3.2.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...