Vulnerability Description
eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dot Project | Dot | < 1.0.3 |
Related Weaknesses (CWE)
References
- https://github.com/eivindfjeldstad/dot/commit/774e4b0c97ca35d2ae40df2cd14428d37dPatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-EIVIFJDOT-564435ExploitThird Party Advisory
- https://github.com/eivindfjeldstad/dot/commit/774e4b0c97ca35d2ae40df2cd14428d37dPatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-EIVIFJDOT-564435ExploitThird Party Advisory
FAQ
What is CVE-2020-7639?
CVE-2020-7639 is a vulnerability with a CVSS score of 5.3 (MEDIUM). eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
How severe is CVE-2020-7639?
CVE-2020-7639 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-7639?
Check the references section above for vendor advisories and patch information. Affected products include: Dot Project Dot.