Skip to content

Prototype Pollution in minimist #276

@TheKingTermux

Description

@TheKingTermux

Description

Minimist prior to 1.2.6 and 0.2.4 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).

Severity Check

  • Low
  • Moderate
  • High
  • Critical

Severity Number

9.8 / 10

CVSS base metrics

  • Attack vector
    Network

  • Attack complexity
    Low

  • Privileges required
    None

  • User interaction
    None

  • Scope
    Unchanged

  • Confidentiality
    High

  • Integrity
    High

  • Availability
    High

  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

  • Weaknesses
    CWE-1321

  • CVE ID
    CVE-2021-44906

  • GHSA ID
    GHSA-xvch-5gv4-984h

Information

Package minimist (npm)

Affected versions

= 1.0.0, < 1.2.6
< 0.2.4

Patched versions
1.2.6
0.2.4

References

Metadata

Metadata

Assignees

Labels

Auto Create IssuesLabel for Auto Created IssuesCriticalThis label for Security Severity onlySecurityLabel for Security Issuesdo-not-autocloseMake bot can't close an Issues or PRs

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions