Vulnerability CVE-2020-7748


Published: 2020-10-20

Description:
This affects the package @tsed/core before 5.65.7. This vulnerability relates to the deepExtend function which is used as part of the utils directory. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.

Type:

CWE-400

(Uncontrolled Resource Consumption ('Resource Exhaustion'))

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.8/10
6.4/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Ts.ed project -> Ts.ed 

 References:
https://github.com/TypedProject/tsed/blob/production/packages/core/src/utils/deepExtends.ts%23L36
https://github.com/TypedProject/tsed/commit/1395773ddac35926cf058fc6da9fb8e82266761b
https://snyk.io/vuln/SNYK-JS-TSEDCORE-1019382

Copyright 2024, cxsecurity.com

 

Back to Top