{"id":"GHSA-897m-rjf5-jp39","summary":"Prototype Pollution in copy-props","details":"The package copy-props before 2.0.5 are vulnerable to Prototype Pollution via the main functionality.","aliases":["CVE-2020-28503"],"modified":"2025-01-14T08:56:52.572897Z","published":"2022-01-06T20:35:05Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2021-03-24T23:59:08Z","nvd_published_at":"2021-03-23T10:15:00Z","cwe_ids":["CWE-1321"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-28503"},{"type":"WEB","url":"https://github.com/gulpjs/copy-props/pull/7"},{"type":"WEB","url":"https://github.com/gulpjs/copy-props/commit/2c738f5c52cfb384b43d977a56a3ab7ce465df9b"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1088047"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-COPYPROPS-1082870"}],"affected":[{"package":{"name":"copy-props","ecosystem":"npm","purl":"pkg:npm/copy-props"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.0.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-897m-rjf5-jp39/GHSA-897m-rjf5-jp39.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"}]}