VYPR

Taffy

by Taffydb

CVEs (1)

  • CVE-2019-10790HigFeb 17, 2020
    risk 0.49cvss 7.5epss 0.02

    taffydb npm module, vulnerable in all versions up to and including 2.7.3, allows attackers to forge adding additional properties into user-input processed by taffy which can allow access to any data items in the DB. taffy sets an internal index for each data item in its DB.…