GHSA-5rrq-pxf6-6jx5

Suggest an improvement
Source
https://github.com/advisories/GHSA-5rrq-pxf6-6jx5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-5rrq-pxf6-6jx5/GHSA-5rrq-pxf6-6jx5.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-5rrq-pxf6-6jx5
Downstream
Published
2022-01-08T00:22:42Z
Modified
2022-01-07T22:20:53Z
Summary
Prototype Pollution in node-forge debug API.
Details

Impact

The forge.debug API had a potential prototype pollution issue if called with untrusted input. The API was only used for internal debug purposes in a safe way and never documented or advertised. It is suspected that uses of this API, if any exist, would likely not have used untrusted inputs in a vulnerable way.

Patches

The forge.debug API and related functions were removed in 1.0.0.

Workarounds

Don't use the forge.debug API directly or indirectly with untrusted input.

References

For more information

If you have any questions or comments about this advisory:

Database specific
{
    "cwe_ids": [
        "CWE-1321"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2022-01-07T22:20:53Z",
    "nvd_published_at": null,
    "severity": "LOW"
}
References

Affected packages

npm / node-forge

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-5rrq-pxf6-6jx5/GHSA-5rrq-pxf6-6jx5.json"