NodeJS/dot-prop/4.1.0
Get, set, or delete a property from a nested object using a dot path
https://www.npmjs.com/package/dot-prop
MIT
1 Security Vulnerabilities
dot-prop Prototype Pollution vulnerability
Published date: 2020-07-29T20:56:59Z
CVE: CVE-2020-8116
Links:
- https://nvd.nist.gov/vuln/detail/CVE-2020-8116
- https://github.com/advisories/GHSA-ff7x-qrg7-qggm
- https://hackerone.com/reports/719856
- https://github.com/sindresorhus/dot-prop/issues/63
- https://github.com/sindresorhus/dot-prop/tree/v4
- https://github.com/sindresorhus/dot-prop/commit/3039c8c07f6fdaa8b595ec869ae0895686a7a0f2
- https://github.com/sindresorhus/dot-prop/commit/c914124f418f55edea27928e89c94d931babe587
Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language constructs such as objects.
Affected versions:
["5.0.0", "5.0.1", "5.1.0", "1.0.0", "1.0.1", "2.0.0", "2.1.0", "2.2.0", "2.3.0", "2.4.0", "3.0.0", "4.0.0", "4.1.0", "4.1.1", "4.2.0"]
Secure versions:
[5.1.1, 5.2.0, 4.2.1, 5.3.0, 6.0.0, 6.0.1, 7.0.0, 7.1.0, 7.1.1, 7.2.0, 8.0.0, 8.0.1, 8.0.2, 9.0.0]
Recommendation:
Update to version 9.0.0.
29 Other Versions
Version | License | Security | Released | |
---|---|---|---|---|
9.0.0 | MIT | 2024-05-09 - 20:31 | about 1 year | |
8.0.2 | MIT | 2023-07-18 - 13:29 | almost 2 years | |
8.0.1 | MIT | 2023-06-29 - 18:14 | almost 2 years | |
8.0.0 | MIT | 2023-04-22 - 06:40 | about 2 years | |
7.2.0 | MIT | 2022-02-17 - 03:46 | about 3 years | |
7.1.1 | MIT | 2022-01-22 - 17:39 | over 3 years | |
7.1.0 | MIT | 2022-01-22 - 07:34 | over 3 years | |
7.0.0 | MIT | 2022-01-21 - 09:55 | over 3 years | |
6.0.1 | MIT | 2020-11-19 - 10:00 | over 4 years | |
6.0.0 | MIT | 2020-10-07 - 21:06 | over 4 years | |
5.3.0 | MIT | 2020-09-06 - 14:14 | over 4 years | |
5.2.0 | MIT | 2019-11-01 - 14:59 | over 5 years | |
5.1.1 | MIT | 2019-10-23 - 09:05 | over 5 years | |
5.1.0 | MIT | 1 | 2019-06-11 - 17:00 | almost 6 years |
5.0.1 | MIT | 1 | 2019-06-07 - 07:15 | almost 6 years |
5.0.0 | MIT | 1 | 2019-04-06 - 15:48 | about 6 years |
4.2.1 | MIT | 2020-08-16 - 11:13 | over 4 years | |
4.2.0 | MIT | 1 | 2017-07-24 - 20:08 | almost 8 years |
4.1.1 | MIT | 1 | 2017-02-18 - 18:25 | about 8 years |
4.1.0 | MIT | 1 | 2016-11-27 - 16:45 | over 8 years |
4.0.0 | MIT | 1 | 2016-09-04 - 16:16 | over 8 years |
3.0.0 | MIT | 1 | 2016-05-19 - 18:27 | almost 9 years |
2.4.0 | MIT | 1 | 2016-03-02 - 09:14 | about 9 years |
2.3.0 | MIT | 1 | 2016-02-25 - 08:48 | about 9 years |
2.2.0 | MIT | 1 | 2015-06-16 - 17:22 | almost 10 years |
2.1.0 | MIT | 1 | 2015-06-04 - 12:54 | almost 10 years |
2.0.0 | MIT | 1 | 2015-04-28 - 15:33 | about 10 years |
1.0.1 | MIT | 1 | 2015-01-24 - 07:27 | over 10 years |
1.0.0 | MIT | 1 | 2015-01-08 - 06:19 | over 10 years |