npm package
steal
pkg:npm/steal
Vulnerabilities (8)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-37265 | — | <= 2.3.0 | — | Sep 20, 2022 | Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js. | ||
| CVE-2022-37259 | — | <= 2.3.0 | — | Sep 20, 2022 | A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the string variable in babel.js. | ||
| CVE-2022-37258 | — | <= 2.3.0 | — | Sep 16, 2022 | Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName variable in npm-convert.js. | ||
| CVE-2022-37260 | — | <= 2.3.0 | — | Sep 15, 2022 | A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the input variable in main.js. | ||
| CVE-2022-37264 | — | <= 2.3.0 | — | Sep 15, 2022 | Prototype pollution vulnerability in stealjs steal 2.2.4 via the optionName variable in main.js. | ||
| CVE-2022-37262 | — | <= 2.3.0 | — | Sep 15, 2022 | A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the source and sourceWithComments variable in main.js. | ||
| CVE-2022-37257 | — | <= 2.3.0 | — | Sep 15, 2022 | Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js. | ||
| CVE-2022-37266 | — | <= 2.3.0 | — | Sep 15, 2022 | Prototype pollution vulnerability in function extend in babel.js in stealjs steal 2.2.4 via the key variable in babel.js. |
- CVE-2022-37265Sep 20, 2022affected <= 2.3.0
Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js.
- CVE-2022-37259Sep 20, 2022affected <= 2.3.0
A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the string variable in babel.js.
- CVE-2022-37258Sep 16, 2022affected <= 2.3.0
Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName variable in npm-convert.js.
- CVE-2022-37260Sep 15, 2022affected <= 2.3.0
A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the input variable in main.js.
- CVE-2022-37264Sep 15, 2022affected <= 2.3.0
Prototype pollution vulnerability in stealjs steal 2.2.4 via the optionName variable in main.js.
- CVE-2022-37262Sep 15, 2022affected <= 2.3.0
A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the source and sourceWithComments variable in main.js.
- CVE-2022-37257Sep 15, 2022affected <= 2.3.0
Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js.
- CVE-2022-37266Sep 15, 2022affected <= 2.3.0
Prototype pollution vulnerability in function extend in babel.js in stealjs steal 2.2.4 via the key variable in babel.js.