Vulnerablity Issue on Flat 5.0.2 #1974
CookieMonster70
started this conversation in
General
Replies: 1 comment
-
Hello @CookieMonster70 - thanks for getting in touch! After looking into your request regarding @hughsk - am I correct in this assessment, surrounding #635? Let me know if you have any more questions @CookieMonster70 - cheers! 🍉 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hi,
Our Security Department informed us, That component flat 5.0.2 we use, has a vulnerability Issue. I got asked if there are any plans, when the package "flat 5.0.2" will be fixed. As far as I know there is a fix, but it hasn't been merged till now. Are there any plans when a new fixed version of "flat 5.0.2" will be released?
#635
Regards Daniele
Message:
The flat package is vulnerable to Prototype Pollution. The unflatten() function in the index.js file allows objects to modify prototype properties via certain accessors such as prototype. A remote attacker can exploit this vulnerability to modify the behavior of object prototypes which, depending on their use in the application, may result in a Denial of Service (DoS), Remote Code Execution (RCE), or other unexpected behavior.
Note: This vulnerability exists due to an incomplete fix for sonatype-2020-0690.
Beta Was this translation helpful? Give feedback.
All reactions