CVE-2023-45827
CVSS V2 None
CVSS V3 None
Description
Dot diver is a lightweight, powerful, and dependency-free TypeScript utility library that provides types and functions to work with object paths in dot notation. In versions prior to 1.0.2 there is a Prototype Pollution vulnerability in the `setByPath` function which can leads to remote code execution (RCE). This issue has been addressed in commit `98daf567` which has been included in release 1.0.2. Users are advised to upgrade. There are no known workarounds to this vulnerability.
Overview
- CVE ID
- CVE-2023-45827
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-11-06T17:25:43.774Z
- Last Modified Date
- 2023-11-06T17:25:43.774Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/clickbar/dot-diver/security/advisories/GHSA-9w5f-mw3p-pj47 | x_refsource_CONFIRM |
https://github.com/clickbar/dot-diver/commit/98daf567390d816fd378ec998eefe2e97f293d5a | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-45827 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45827 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 10:12:43 | Added to TrackCVE |