TypeORM vulnerable to MAID and Prototype Pollution
Critical severity
GitHub Reviewed
Published
May 7, 2021
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Description
Published by the National Vulnerability Database
Sep 18, 2020
Reviewed
Apr 28, 2021
Published to the GitHub Advisory Database
May 7, 2021
Last updated
Jan 30, 2023
Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks.
References