VYPR
Vendor

Stealjs

Products
1
CVEs
8
Across products
8
Status
Private

Products

1

Recent CVEs

8
  • CVE-2022-37265CriSep 20, 2022
    risk 0.64cvss 9.8epss 0.01

    Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js.

  • CVE-2022-37258CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName variable in npm-convert.js.

  • CVE-2022-37264CriSep 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Prototype pollution vulnerability in stealjs steal 2.2.4 via the optionName variable in main.js.

  • CVE-2022-37266CriSep 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Prototype pollution vulnerability in function extend in babel.js in stealjs steal 2.2.4 via the key variable in babel.js.

  • CVE-2022-37257CriSep 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js.

  • CVE-2022-37259HigSep 20, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the string variable in babel.js.

  • CVE-2022-37260HigSep 15, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the input variable in main.js.

  • CVE-2022-37262HigSep 15, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the source and sourceWithComments variable in main.js.