nathan7/fun-map

nathan7/fun-map

Releases11
Frequency6 days 20 hours
Last Release
Stars1
a few functional utilities for pretending that JS objects are Clojure string maps.

CVE History

CVEPublishedCVSS v3CVSS v2
8.1 HIGH6.8 MEDIUM

fun-map through 3.3.1 is vulnerable to Prototype Pollution. The function assocInM could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.