CVE-2018-16472 PUBLISHED

A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects through the prototype chain causing a DoS attack.

EPSS 0.52% · 66.6th percentile

Risk Scores

EPSS Score
0.52%
66.6th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSnode-cached-path-relative0, 1.0.1-1

Timeline

References

Open in Interactive Console →