CVE-2020-15256
Description
A prototype pollution vulnerability has been found in object-path <= 0.11.4 affecting the set() method. The vulnerability is limited to the includeInheritedProps mode (if version >= 0.11.0 is used), which has to be explicitly enabled by creating a new instance of object-path and setting the option includeInheritedProps: true, or by using the default withInheritedProps instance. The default operating mode is not affected by the vulnerability if version >= 0.11.0 is used. Any usage of set() in versions < 0.11.0 is vulnerable. The issue is fixed in object-path version 0.11.5 As a workaround, don't use the includeInheritedProps: true options or the withInheritedProps instance if using a version >= 0.11.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
object-pathnpm | < 0.11.5 | 0.11.5 |
Affected products
3- cpe:2.3:a:object-path_project:object-path:*:*:*:*:*:node.js:*:*Range: <0.11.5
- mariocasciaro/object-pathv5Range: < 0.11.5
Patches
Vulnerability mechanics
References
4- github.com/mariocasciaro/object-path/commit/2be3354c6c46215c7635eb1b76d80f1319403c68nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-cwx2-736x-mf6wghsaADVISORY
- github.com/mariocasciaro/object-path/security/advisories/GHSA-cwx2-736x-mf6wnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-15256ghsaADVISORY
News mentions
0No linked articles in our index yet.