CVE-2020-28271
critical
CVSS v3
9.8
CVSS v2
7.5
VIR risk
9.8
Description
Prototype Pollution in deephas
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: vulnerabilitylab@mend.io — https://github.com/sharpred/deepHas/commit/2fe011713a6178c50f7deb6f039a8e5435981e20
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| npm | deephas | >=1.0.0,<=1.0.5 | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| sharpred | deephas | {"startIncluding":"1.0.0","endIncluding":"1.0.5"} | |
References
CWEs
CWE-1321
Verify integrity in audit chain (admin only). AS-IS.