unamednada / unamednada.github.io

0 stars 0 forks source link

[SECURITY]Prototype Pollution in async #31

Closed unamednada closed 2 years ago

unamednada commented 2 years ago

***Vulnerability found by dependabot

A vulnerability exists in Async through 3.2.1 for 3.x and through 2.6.3 for 2.x (fixed in 3.2.2 and 2.6.4), which could let a malicious user obtain privileges via the mapValues() method.