CVE-2021-3766

Improperly Controlled Modification of Dynamically-Determined Object Attributes in npm/objection

Identifiers

CVE-2021-3766

Package Slug

npm/objection

Vulnerability

Improperly Controlled Modification of Dynamically-Determined Object Attributes

Description

objection.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Affected Versions

All versions before 3.0.0-alpha.5

Solution

Upgrade to version 3.0.0-alpha.5 or above.

Last Modified

2021-09-16

source