VDB

CVE-2020-7765

CVE-2020-7765 PUBLISHED CVSS 5.599999904632568 MEDIUM

This affects the package @firebase/util before 0.3.4. This vulnerability relates to the deepExtend function within the DeepCopy.ts file. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.

EPSS 0.57% · 45.9th percentile

Risk Scores

CVSS 3.1
5.599999904632568
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
EPSS Score
0.57%
45.9th percentile

Affected Products

VendorProductVersions
n/a@firebase/utilunspecified
firebaseutil0
googlefirebase\/util0

Timeline

  • Nov 16, 2020 CVE Published
  • Dec 1, 2020 CVE Updated
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 25, 2021 EPSS Score
  • Oct 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 2, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 4, 2022 EPSS Score
  • Jul 6, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›