1 results (0.001 seconds)

CVSS: 9.0EPSS: 0%CPEs: 1EXPL: 2

21 Dec 2022 — A vulnerability was found in LinkedIn dustjs up to 2.x and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/linkedin/dustjs/commit/ddb6523832465d38c9d80189e9de60519ac307c3 • CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') •