VDB
CVE-2020-7765
CVE-2020-7765
PUBLISHED
CVSS 5.599999904632568 MEDIUM
This affects the package @firebase/util before 0.3.4. This vulnerability relates to the deepExtend function within the DeepCopy.ts file. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.
EPSS 0.57% · 45.9th percentile
Risk Scores
CVSS 3.1
5.599999904632568
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
EPSS Score
0.57%
45.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | @firebase/util | unspecified |
| firebase | util | 0 |
| firebase\/util | 0 |
Timeline
- Nov 16, 2020 CVE Published
- Dec 1, 2020 CVE Updated
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Oct 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 2, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 4, 2022 EPSS Score
- Jul 6, 2022 EPSS Score