Modification of Assumed-Immutable Data Vulnerability in Merge-Deep Node Module
CVE-2018-3722

8.8HIGH

Key Information:

Vendor

Hackerone

Vendor
CVE Published:
7 June 2018

What is CVE-2018-3722?

The Merge-Deep node module prior to version 3.0.1 is susceptible to a Modification of Assumed-Immutable Data (MAID) vulnerability. This flaw allows an attacker to alter the prototype of 'Object' through the proto property. As a result, malicious users can add or change properties that will be inherited by all object instances, potentially leading to inconsistent object behaviors and security implications within an application utilizing this module.

Affected Version(s)

merge-deep node module Versions before 3.0.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.