7.3
CVSSv3

CVE-2020-8116

Published: 04/02/2020 Updated: 05/08/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 7.3 | Impact Score: 3.4 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Prototype pollution vulnerability in dot-prop npm package versions prior to 4.2.1 and versions 5.x prior to 5.1.1 allows an malicious user to add arbitrary properties to JavaScript language constructs such as objects.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dot-prop project dot-prop

Vendor Advisories

Synopsis Moderate: rh-nodejs12-nodejs security update Type/Severity Security Advisory: Moderate Topic An update for rh-nodejs12-nodejs is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring Syst ...
Synopsis Moderate: rh-nodejs10-nodejs security update Type/Severity Security Advisory: Moderate Topic An update for rh-nodejs10-nodejs is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring Syst ...
Synopsis Moderate: nodejs:10 security update Type/Severity Security Advisory: Moderate Topic An update for the nodejs:10 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) ...
Synopsis Moderate: nodejs:12 security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for the nodejs:12 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring S ...
Synopsis Moderate: nodejs:12 security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for the nodejs:12 module is now available for Red Hat Enterprise Linux 81 Extended Update SupportRed Hat Product Security has rated this update as having a security impact of Moderate A Comm ...

Github Repositories

Python script to filter and sort the OWASP Dependency Checker JSON output.

DependencyCheckParser Python script to filter and sort the OWASP Dependency Checker JSON output Example: python DepChecker_parserpy -i DepChecker_output_SAMPLEjson required argument: --input INPUT, -i INPUT Path to input OWASP Dependency Checker JSON file to parse optional arguments: -h, --help Show this help message and exit --filter, -f