sharpred/deepHas

sharpred/deepHas

Releases7
Frequency1 year 9 months
Last Release
Stars1
test for existence of nested object key and optionally return that key

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH

deepHas provides a test for the existence of a nested object key and optionally returns that key. A prototype pollution vulnerability exists in version 1.0.7 of the deephas npm package that allows an attacker to modify global object behavior. This issue was fixed in version 1.0.8.

9.8 CRITICAL7.5 HIGH

Prototype pollution vulnerability in 'deephas' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.