Vulnerabilities
Vulnerable Software
Dot Project:  >> Dot  Security Vulnerabilities
eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
CVSS Score
5.3
EPSS Score
0.003
Published
2020-04-06
The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control the given template or if they can control the value set on Object.prototype.
CVSS Score
8.8
EPSS Score
0.01
Published
2020-03-15


Contact Us

Shodan ® - All rights reserved