Prototype Pollution in Controlled-Merge Plugin by hlfshell
CVE-2020-28268
7.5HIGH
What is CVE-2020-28268?
A vulnerability exists in the 'controlled-merge' plugin, specifically in versions 1.0.0 through 1.2.0. This issue allows an attacker to exploit prototype pollution, which can result in a denial of service. In certain scenarios, this vulnerability can also lead to remote code execution, posing a significant risk to users of the affected plugin. Users are advised to upgrade to the latest version to mitigate the risk associated with this vulnerability.
Affected Version(s)
controlled-merge 1.0.0, 1.0.1, 1.1.0, 1.2.0
