Home 3.6.0 (custom) before 3.6.1
affected
Description
JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker may alter the application logic, bypass security checks, cause a DoS or achieve remote code execution.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Product status
References
github.com/mafintosh/protocol-buffers-schema/pull/70
morielharush.github.io/...uffers-schema-prototype-pollution/