HIGH 7.1 npm
Use of Potentially Dangerous Function in mixme
GHSA-79jw-6wg7-r9g4 · CVE-2021-29491
Published · Modified
Description
Impact
In Node.js mixme v0.5.0, an attacker can add or alter properties of an object via 'proto' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at risk causing a potential denial of service (DoS).
Patches
The problem is corrected starting with version 0.5.1.
References
Issue: https://github.com/adaltas/node-mixme/issues/1
Commit: https://github.com/adaltas/node-mixme/commit/cfd5fbfc32368bcf7e06d1c5985ea60e34cd4028
Ready to move
Start Securing
Free, no credit card | First findings in minutes