Description
Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1149 | Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks. |
Github GHSA |
GHSA-pf2j-9qmp-jqr2 | TypeORM vulnerable to MAID and Prototype Pollution |
References
| Link | Providers |
|---|---|
| https://hackerone.com/reports/869574 |
|
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-08-04T09:48:25.595Z
Reserved: 2020-01-28T00:00:00.000Z
Link: CVE-2020-8158
No data.
Status : Modified
Published: 2020-09-18T21:15:12.747
Modified: 2024-11-21T05:38:24.343
Link: CVE-2020-8158
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA