CVE-2020-7598

Updated on 11 Mar 2020

Severity

5.6 Medium severity

Details

CVSS score
5.6
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Overview

About vulnerability

minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a “constructor” or “proto” payload.

Details

Affected packages:
minimist @ 1.2.0 (+38 more)
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a “constructor” or “proto” payload.

Fixes