Prototype Poisoning Vulnerability in Hoek Library by Happi
CVE-2020-36604

8.1HIGH

Key Information:

Vendor

Hapijs

Status
Vendor
CVE Published:
23 September 2022

What is CVE-2020-36604?

The vulnerability identified in the Hoek library allows for prototype poisoning, specifically within its clone function. This could enable an attacker to manipulate the object's prototype chain, potentially impacting applications that rely on this library for data handling. To mitigate this risk, users are encouraged to upgrade to versions 8.5.1 or higher, or 9.0.3 or higher, thereby ensuring their applications are safeguarded against such exploits.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.