← All CVEs

CVE-2020-7774

high · 7.3

The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.

7.3
CVSS
69.4%
EPSS (exploit prob.)
99th
EPSS percentile
2020-11-17
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Weaknesses

CWE-1321

Affected products

VendorProductAffected versions
y18n_projecty18n< 3.2.2
y18n_projecty18n>= 5.0.0, < 5.0.5
y18n_projecty18n4.0.0
oraclegraalvm19.3.5
oraclegraalvm20.3.1.2
oraclegraalvm21.0.0.2
siemenssinec_infrastructure_network_services< 1.0.1.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-7774