Vulnerability Description
All versions of the package rangy are vulnerable to Prototype Pollution when using the extend() function in file rangy-core.js.The function uses recursive merge which can lead an attacker to modify properties of the Object.prototype
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rangy Project | Rangy | - |
Related Weaknesses (CWE)
References
- https://github.com/timdown/rangy/issues/478ExploitIssue TrackingThird Party Advisory
- https://security.snyk.io/vuln/SNYK-JS-RANGY-3175702ExploitThird Party Advisory
- https://github.com/timdown/rangy/issues/478ExploitIssue TrackingThird Party Advisory
- https://security.snyk.io/vuln/SNYK-JS-RANGY-3175702ExploitThird Party Advisory
FAQ
What is CVE-2023-26102?
CVE-2023-26102 is a vulnerability with a CVSS score of 7.5 (HIGH). All versions of the package rangy are vulnerable to Prototype Pollution when using the extend() function in file rangy-core.js.The function uses recursive merge which can lead an attacker to modify pr...
How severe is CVE-2023-26102?
CVE-2023-26102 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-26102?
Check the references section above for vendor advisories and patch information. Affected products include: Rangy Project Rangy.