CVE-2020-28495
Prototype pollution in total.js
7.3
HIGH
CVSS 3.1
EPSS 6.1%
Description
There is a prototype pollution vulnerability in the package total.js before version 3.4.7. The set function can be used to set a value into the object according to the path. However the keys of the path being set are not properly sanitized, leading to a prototype pollution vulnerability. The impact depends on the application. In some cases it is possible to achieve Denial of service (DoS), Remote Code Execution or Property Injection.
How to fix CVE-2020-28495
To remediate CVE-2020-28495, upgrade the affected package to a fixed version below.
- —upgrade to 3.4.7 or later
Is CVE-2020-28495 being exploited?
Moderate — EPSS is 6.1%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 3.4.7
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |