Substack Minimist 0.0.9 for Node.js

CPE Details

Substack Minimist 0.0.9 for Node.js
0.0.9
2020-03-13
18h03 +00:00
2020-03-13
18h03 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:substack:minimist:0.0.9:*:*:*:*:node.js:*:*

Informations

Vendor

substack

Product

minimist

Version

0.0.9

Target Software

node.js

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-44906 2022-03-17 12h05 +00:00 Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
9.8
Critical
CVE-2020-7598 2020-03-11 20h40 +00:00 minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
5.6
Medium