{"id":"GHSA-3xph-cp8f-2229","summary":"Prototype Pollution in @fabiocaccamo/utils.js","details":"utils.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution').","aliases":["CVE-2021-3815"],"modified":"2023-11-08T04:06:25.432401Z","published":"2021-12-10T20:31:32Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2021-12-09T18:05:12Z","nvd_published_at":"2021-12-08T17:15:00Z","cwe_ids":["CWE-1321"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-3815"},{"type":"WEB","url":"https://github.com/fabiocaccamo/utils.js/commit/102efafb291ce1916985514440d3bf8a6826890a"},{"type":"PACKAGE","url":"https://github.com/fabiocaccamo/utils.js"},{"type":"WEB","url":"https://huntr.dev/bounties/20f48c63-f078-4173-bcac-a9f34885f2c0"}],"affected":[{"package":{"name":"@fabiocaccamo/utils.js","ecosystem":"npm","purl":"pkg:npm/%40fabiocaccamo/utils.js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.17.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-3xph-cp8f-2229/GHSA-3xph-cp8f-2229.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H"}]}