CVE-2020-7792
Prototype Pollution in mout
7.5
HIGH
CVSS 3.1
EPSS 0.98%
Description
This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn 'mixes objects into the target object, recursively mixing existing child objects as well'. In both cases, the key used to access the target object recursively is not checked, leading to a Prototype Pollution.
How to fix CVE-2020-7792
To remediate CVE-2020-7792, upgrade the affected package to a fixed version below.
- —upgrade to 1.2.3 or later
Is CVE-2020-7792 being exploited?
Low — EPSS is 1.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.2.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |