Prototype Pollution in y18n
High severity
GitHub Reviewed
Published
Mar 29, 2021
to the GitHub Advisory Database
•
Updated Nov 29, 2023
Package
Affected versions
< 3.2.2
= 4.0.0
>= 5.0.0, < 5.0.5
Patched versions
3.2.2
4.0.1
5.0.5
Description
Published by the National Vulnerability Database
Nov 17, 2020
Reviewed
Mar 12, 2021
Published to the GitHub Advisory Database
Mar 29, 2021
Last updated
Nov 29, 2023
Overview
The npm package
y18n
before versions 3.2.2, 4.0.1, and 5.0.5 is vulnerable to Prototype Pollution.POC
Recommendation
Upgrade to version 3.2.2, 4.0.1, 5.0.5 or later.
References