Prototype Pollution Vulnerability in Undefsafe by Remy
CVE-2019-10795

6.3MEDIUM

Key Information:

Vendor

Snyk

Status
Vendor
CVE Published:
18 February 2020

What is CVE-2019-10795?

The Undefsafe package, prior to version 2.0.3, is susceptible to a security issue known as Prototype Pollution. An attacker could exploit the 'a' method to manipulate or add properties to Object.prototype using a specially crafted proto payload, potentially compromising the integrity of applications that rely on this functionality. It is crucial for developers using Undefsafe to update to the latest version to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

undefsafe All versions prior to version 2.0.3

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.