Dset ProjectCVEs & Vulnerabilities
2 CVEs affecting Dset Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
dset 2
CVE-2022-25645HIGH
All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if the top-level path contains __proto__, constructor or protorype. By crafting a malicious object, it is possible to bypass this check and achieve prototype pollution.
1 May 2022
8.1
CVSS
CVE-2020-28277CRITICAL
Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
29 Dec 2020
9.8
CVSS
← PrevPage 1 / 1Next →