Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown
CVE-2020-7770
Disclosure Date: November 12, 2020 (last updated February 22, 2025)
This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, however it does not properly check the key being set, leading to a prototype pollution.
0
Attacker Value
Unknown
CVE-2020-8268
Disclosure Date: November 09, 2020 (last updated February 22, 2025)
Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor.
0