Vulnerablity Issue on Flat 5.0.2 #1974
CookieMonster70
started this conversation in
General
Replies: 1 comment
-
Hello @CookieMonster70 - thanks for getting in touch! After looking into your request regarding @hughsk - am I correct in this assessment, surrounding #635? Let me know if you have any more questions @CookieMonster70 - cheers! 🍉 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hi,
Our Security Department informed us, That component flat 5.0.2 we use, has a vulnerability Issue. I got asked if there are any plans, when the package "flat 5.0.2" will be fixed. As far as I know there is a fix, but it hasn't been merged till now. Are there any plans when a new fixed version of "flat 5.0.2" will be released?
#635
Regards Daniele
Message:
The flat package is vulnerable to Prototype Pollution. The unflatten() function in the index.js file allows objects to modify prototype properties via certain accessors such as prototype. A remote attacker can exploit this vulnerability to modify the behavior of object prototypes which, depending on their use in the application, may result in a Denial of Service (DoS), Remote Code Execution (RCE), or other unexpected behavior.
Note: This vulnerability exists due to an incomplete fix for sonatype-2020-0690.
Beta Was this translation helpful? Give feedback.
All reactions