Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2022-25907
The package ts-deepmerge before 2.0.2 are vulnerable to Prototype Pollution due to missing sanitization of the merge function.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.003
EPSS Ranking
54.3%
CVSS Severity
CVSS v3 Score
7.5
References
https://github.com/voodoocreation/ts-deepmerge/commit/9be5148773343c57be9de39728d6ead18eddf10b
https://github.com/voodoocreation/ts-deepmerge/releases/tag/2.0.2
https://security.snyk.io/vuln/SNYK-JS-TSDEEPMERGE-2959975
https://github.com/voodoocreation/ts-deepmerge/commit/9be5148773343c57be9de39728d6ead18eddf10b
https://github.com/voodoocreation/ts-deepmerge/releases/tag/2.0.2
https://security.snyk.io/vuln/SNYK-JS-TSDEEPMERGE-2959975
Products affected by CVE-2022-25907
Typescript Deep Merge Project
»
Typescript Deep Merge
»
Version:
1.0.0
cpe:2.3:a:typescript_deep_merge_project:typescript_deep_merge:1.0.0
Typescript Deep Merge Project
»
Typescript Deep Merge
»
Version:
1.0.1
cpe:2.3:a:typescript_deep_merge_project:typescript_deep_merge:1.0.1
Typescript Deep Merge Project
»
Typescript Deep Merge
»
Version:
1.0.2
cpe:2.3:a:typescript_deep_merge_project:typescript_deep_merge:1.0.2
Typescript Deep Merge Project
»
Typescript Deep Merge
»
Version:
1.0.3
cpe:2.3:a:typescript_deep_merge_project:typescript_deep_merge:1.0.3
Typescript Deep Merge Project
»
Typescript Deep Merge
»
Version:
1.0.4
cpe:2.3:a:typescript_deep_merge_project:typescript_deep_merge:1.0.4
Typescript Deep Merge Project
»
Typescript Deep Merge
»
Version:
1.0.5
cpe:2.3:a:typescript_deep_merge_project:typescript_deep_merge:1.0.5
Typescript Deep Merge Project
»
Typescript Deep Merge
»
Version:
1.0.6
cpe:2.3:a:typescript_deep_merge_project:typescript_deep_merge:1.0.6
Typescript Deep Merge Project
»
Typescript Deep Merge
»
Version:
1.0.7
cpe:2.3:a:typescript_deep_merge_project:typescript_deep_merge:1.0.7
Typescript Deep Merge Project
»
Typescript Deep Merge
»
Version:
1.0.8
cpe:2.3:a:typescript_deep_merge_project:typescript_deep_merge:1.0.8
Typescript Deep Merge Project
»
Typescript Deep Merge
»
Version:
1.1.0
cpe:2.3:a:typescript_deep_merge_project:typescript_deep_merge:1.1.0
Typescript Deep Merge Project
»
Typescript Deep Merge
»
Version:
2.0.0
cpe:2.3:a:typescript_deep_merge_project:typescript_deep_merge:2.0.0
Typescript Deep Merge Project
»
Typescript Deep Merge
»
Version:
2.0.1
cpe:2.3:a:typescript_deep_merge_project:typescript_deep_merge:2.0.1
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved