CVE-2020-8147
Prototype Pollution
EPSS 1.1%
Description
All versions of `utils-extend` are vulnerable to prototype pollution. The `extend` function does not restrict the modification of an Object's prototype, which may allow an attacker to add or modify an existing property that will exist on all objects. ## Recommendation No fix is currently available. Consider using an alternative package until a fix is made available.
How to fix CVE-2020-8147
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- npm/utils-extend—no fix listed
Is CVE-2020-8147 being exploited?
Low — EPSS is 1.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 0.0.0