Skip to content

Prevent attacker to add or alter properties of an object

High
wdavidw published GHSA-84p7-fh9c-6g8h Sep 16, 2021

Package

npm mixme (npm)

Affected versions

<0.5.1

Patched versions

0.5.2

Description

Impact

When copying properties from a source object to a target object, the target object can gain access to certain properties of the source object and modify their content.

Patches

The problem was patch with a more agressive discovery of secured properties to filter out.

Workarounds

Update to the latest version of mixme,

Severity

High

CVE ID

CVE-2021-29491

Weaknesses

No CWEs