Vulnerability Description
The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via the set, unSet, pushVal and pullVal functions.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Irrelon | \@Irrelon\/Path | < 4.7.0 |
| Irrelon | Irrelon-Path | < 4.7.0 |
Related Weaknesses (CWE)
References
- https://github.com/Irrelon/irrelon-path/commit/8a126b160c1a854ae511659c111413ad9PatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-IRRELONPATH-598672ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-IRRELONPATH-598673ExploitThird Party Advisory
- https://github.com/Irrelon/irrelon-path/commit/8a126b160c1a854ae511659c111413ad9PatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-IRRELONPATH-598672ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-IRRELONPATH-598673ExploitThird Party Advisory
FAQ
What is CVE-2020-7708?
CVE-2020-7708 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via the set, unSet, pushVal and pullVal functions.
How severe is CVE-2020-7708?
CVE-2020-7708 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-7708?
Check the references section above for vendor advisories and patch information. Affected products include: Irrelon \@Irrelon\/Path, Irrelon Irrelon-Path.