Vulnerabilities
Vulnerable Software
Uglifyjs Project:  Security Vulnerabilities
Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.js. NOTE: the vendor considers this an invalid report.
CVSS Score
9.8
EPSS Score
0.002
Published
2022-10-20
The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which might allow attackers to bypass security mechanisms or possibly have unspecified other impact by leveraging improperly rewritten Javascript.
CVSS Score
9.8
EPSS Score
0.003
Published
2017-01-23
The uglify-js package before 2.6.0 for Node.js allows attackers to cause a denial of service (CPU consumption) via crafted input in a parse call, aka a "regular expression denial of service (ReDoS)."
CVSS Score
7.5
EPSS Score
0.009
Published
2017-01-23


Contact Us

Shodan ® - All rights reserved