Vulnerability Details CVE-2020-15256
A prototype pollution vulnerability has been found in `object-path` <= 0.11.4 affecting the `set()` method. The vulnerability is limited to the `includeInheritedProps` mode (if version >= 0.11.0 is used), which has to be explicitly enabled by creating a new instance of `object-path` and setting the option `includeInheritedProps: true`, or by using the default `withInheritedProps` instance. The default operating mode is not affected by the vulnerability if version >= 0.11.0 is used. Any usage of `set()` in versions < 0.11.0 is vulnerable. The issue is fixed in object-path version 0.11.5 As a workaround, don't use the `includeInheritedProps: true` options or the `withInheritedProps` instance if using a version >= 0.11.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.7%
CVSS Severity
CVSS v3 Score 7.7
CVSS v2 Score 6.8
Products affected by CVE-2020-15256
-
cpe:2.3:a:object-path_project:object-path:0.0.1
-
cpe:2.3:a:object-path_project:object-path:0.1.0
-
cpe:2.3:a:object-path_project:object-path:0.1.2
-
cpe:2.3:a:object-path_project:object-path:0.1.3
-
cpe:2.3:a:object-path_project:object-path:0.10.0
-
cpe:2.3:a:object-path_project:object-path:0.11.0
-
cpe:2.3:a:object-path_project:object-path:0.11.1
-
cpe:2.3:a:object-path_project:object-path:0.11.2
-
cpe:2.3:a:object-path_project:object-path:0.11.3
-
cpe:2.3:a:object-path_project:object-path:0.11.4
-
cpe:2.3:a:object-path_project:object-path:0.2.0
-
cpe:2.3:a:object-path_project:object-path:0.2.1
-
cpe:2.3:a:object-path_project:object-path:0.3.0
-
cpe:2.3:a:object-path_project:object-path:0.4.0
-
cpe:2.3:a:object-path_project:object-path:0.5.0
-
cpe:2.3:a:object-path_project:object-path:0.5.1
-
cpe:2.3:a:object-path_project:object-path:0.6.0
-
cpe:2.3:a:object-path_project:object-path:0.7.0
-
cpe:2.3:a:object-path_project:object-path:0.8.0
-
cpe:2.3:a:object-path_project:object-path:0.8.1
-
cpe:2.3:a:object-path_project:object-path:0.9.0
-
cpe:2.3:a:object-path_project:object-path:0.9.1
-
cpe:2.3:a:object-path_project:object-path:0.9.2
-
cpe:2.3:a:object-path_project:object-path:0.9.3