CVE-2020-7608

Updated on 16 Mar 2020

Severity

5.3 Medium severity

Details

CVSS score
5.3
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Overview

About vulnerability

yargs-parser could be tricked into adding or modifying properties of Object.prototype using a “proto” payload.

Details

Affected packages:
next @ 2.4.9 (+58 more)
yargs-parser could be tricked into adding or modifying properties of Object.prototype using a “proto” payload.

Fixes