668
VMScore

CVE-2018-3750

Published: 03/07/2018 Updated: 23/08/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

deep extend project deep extend

Vendor Advisories

Synopsis Moderate: rh-nodejs8-nodejs security update Type/Severity Security Advisory: Moderate Topic An update for rh-nodejs8-nodejs is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System ...
Debian Bug report logs - #926616 CVE-2018-3750: Prototype Pollution Package: node-deep-extend; Maintainer for node-deep-extend is Debian Javascript Maintainers &lt;pkg-javascript-devel@listsaliothdebianorg&gt;; Source for node-deep-extend is src:node-deep-extend (PTS, buildd, popcon) Reported by: Jeff Cliff &lt;jeffreycliff@gm ...