Vulnerabilities
Vulnerable Software
This affects the package com.graphhopper:graphhopper-web-bundle before 3.2, from 4.0-pre1 and before 4.0. The URL parser could be tricked into adding or modifying properties of Object.prototype using a constructor or __proto__ payload.
CVSS Score
5.4
EPSS Score
0.003
Published
2021-07-21


Contact Us

Shodan ® - All rights reserved