Vulnerability Description
bodymen before 1.1.1 is vulnerable to Prototype Pollution. The handler function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bodymen Project | Bodymen | < 1.1.1 |
Related Weaknesses (CWE)
References
- https://github.com/diegohaz/bodymen/commit/5d52e8cf360410ee697afd90937e6042c3a86PatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-BODYMEN-548897ExploitThird Party Advisory
- https://github.com/diegohaz/bodymen/commit/5d52e8cf360410ee697afd90937e6042c3a86PatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-BODYMEN-548897ExploitThird Party Advisory
FAQ
What is CVE-2019-10792?
CVE-2019-10792 is a vulnerability with a CVSS score of 6.3 (MEDIUM). bodymen before 1.1.1 is vulnerable to Prototype Pollution. The handler function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
How severe is CVE-2019-10792?
CVE-2019-10792 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10792?
Check the references section above for vendor advisories and patch information. Affected products include: Bodymen Project Bodymen.