Vulnerability Description
vega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could be tricked into adding or modifying properties of the Object.prototype.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vega Project | Vega | < 1.13.1 |
Related Weaknesses (CWE)
References
- https://github.com/vega/vega/commit/8f33a0b5170d7de4f12fc248ec0901234342367bPatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-VEGAUTIL-559223ExploitThird Party Advisory
- https://github.com/vega/vega/commit/8f33a0b5170d7de4f12fc248ec0901234342367bPatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-VEGAUTIL-559223ExploitThird Party Advisory
FAQ
What is CVE-2019-10806?
CVE-2019-10806 is a vulnerability with a CVSS score of 4.3 (MEDIUM). vega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could be tricked into adding or modifying properties of the Object.prototype.
How severe is CVE-2019-10806?
CVE-2019-10806 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10806?
Check the references section above for vendor advisories and patch information. Affected products include: Vega Project Vega.