Vulnerability Description
utilitify prior to 1.0.3 allows modification of object properties. The merge method could be tricked into adding or modifying properties of the Object.prototype.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xcritical.Software | Utilitify | < 1.0.3 |
Related Weaknesses (CWE)
References
- https://github.com/xcritical-software/utilitify/commit/88d6e27009823338bf319ffb7
- https://snyk.io/vuln/SNYK-JS-UTILITIFY-559497ExploitPatchThird Party Advisory
- https://github.com/xcritical-software/utilitify/commit/88d6e27009823338bf319ffb7
- https://snyk.io/vuln/SNYK-JS-UTILITIFY-559497ExploitPatchThird Party Advisory
FAQ
What is CVE-2019-10808?
CVE-2019-10808 is a vulnerability with a CVSS score of 8.8 (HIGH). utilitify prior to 1.0.3 allows modification of object properties. The merge method could be tricked into adding or modifying properties of the Object.prototype.
How severe is CVE-2019-10808?
CVE-2019-10808 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10808?
Check the references section above for vendor advisories and patch information. Affected products include: Xcritical.Software Utilitify.