This repository has been archived by the owner on Feb 3, 2023. It is now read-only.
ramda-0.23.0.tgz: 1 vulnerabilities (highest severity is: 9.1) #45
Labels
security vulnerability
Security vulnerability detected by Mend
A practical functional library for JavaScript programmers.
Library home page: https://registry.npmjs.org/ramda/-/ramda-0.23.0.tgz
Vulnerabilities
Details
Vulnerable Library - ramda-0.23.0.tgz
A practical functional library for JavaScript programmers.
Library home page: https://registry.npmjs.org/ramda/-/ramda-0.23.0.tgz
Dependency Hierarchy:
Found in base branch: main
Vulnerability Details
** DISPUTED ** Prototype poisoning in function mapObjIndexed in Ramda 0.27.0 and earlier allows attackers to compromise integrity or availability of application via supplying a crafted object (that contains an own property "proto") as an argument to the function. NOTE: the vendor disputes this because the observed behavior only means that a user can create objects that the user didn't know would contain custom prototypes.
Publish Date: 2022-05-10
URL: CVE-2021-42581
CVSS 3 Score Details (9.1)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42581
Release Date: 2022-05-10
Fix Resolution: 0.27.1
The text was updated successfully, but these errors were encountered: