GHSA-22h7-7wwg-qmgg
UNKNOWNVersions of @hapi/hoek prior to 8.5.1 and 9.0.3 are vulnerable to Prototype Pollution. The clone function fails to prevent the modification of the Object prototype when passed specially-crafted input. Attackers may use this to change existing properties that exist in all objects, which may lead to Denial of Service or Remote Code Execution in specific circumstances.
- Affected
- >=8.3.2, <8.5.1, >=9.0.0, <9.0.3
- Fixed in
- not stated
- Weakness
- CWE-1321
- Published
- 2020-09-04
- Source
- osv