668
VMScore

CVE-2019-10747

Published: 23/08/2019 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

set-value is vulnerable to Prototype Pollution in versions lower than 3.0.1. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using any of the constructor, prototype and _proto_ payloads.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

set-value project set-value

Vendor Advisories

Synopsis Moderate: nodejs:12 security update Type/Severity Security Advisory: Moderate Topic An update for the nodejs:12 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) ...
Synopsis Moderate: rh-nodejs12-nodejs security update Type/Severity Security Advisory: Moderate Topic An update for rh-nodejs12-nodejs is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring Syst ...
Debian Bug report logs - #941189 node-set-value: CVE-2019-10747 Package: src:node-set-value; Maintainer for src:node-set-value is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 26 Sep 2019 05:15:01 UTC Severity: important ...
Debian Bug report logs - #994448 node-set-value: CVE-2021-23440 - type confusion allows bypass of CVE-2019-10747 Package: node-set-value; Maintainer for node-set-value is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Source for node-set-value is src:node-set-value (PTS, buildd, popcon) Reporte ...

Github Repositories

Parses, summarizes, and prints "npm audit" json output to markdown for nVision reports

npm-deps-parser Parses, summarizes, and prints "npm audit" json output to markdown Because neither making sense out of npm audit nor manually writing markdown tables is fun Caveats Will need to parse the CSV rating or get it from an api Usage The fastest way to use the parser is to pass the npm audit --json output as stdin To do so run the following from the folde