668
VMScore

CVE-2019-10746

Published: 23/08/2019 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

mixin-deep is vulnerable to Prototype Pollution in versions prior to 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mixin-deep project mixin-deep

mixin-deep project mixin-deep 2.0.0

fedoraproject fedora 30

fedoraproject fedora 31

oracle communications cloud native core network function cloud native environment 1.4.0

Vendor Advisories

Debian Bug report logs - #932500 vulnerability: CVE-2019-10746: prototype pollution Package: node-mixin-deep; Maintainer for node-mixin-deep is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Source for node-mixin-deep is src:node-mixin-deep (PTS, buildd, popcon) Reported by: Paolo Greppi <pa ...
Synopsis Moderate: nodejs:12 security update Type/Severity Security Advisory: Moderate Topic An update for the nodejs:12 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) ...
Synopsis Moderate: rh-nodejs12-nodejs security update Type/Severity Security Advisory: Moderate Topic An update for rh-nodejs12-nodejs is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring Syst ...

Github Repositories

Parses, summarizes, and prints "npm audit" json output to markdown for nVision reports

npm-deps-parser Parses, summarizes, and prints "npm audit" json output to markdown Because neither making sense out of npm audit nor manually writing markdown tables is fun Caveats Will need to parse the CSV rating or get it from an api Usage The fastest way to use the parser is to pass the npm audit --json output as stdin To do so run the following from the folde