Possible prototype pollution in metadata record, when using meta decorator
Description
Published by the National Vulnerability Database
Apr 28, 2023
Published to the GitHub Advisory Database
May 1, 2023
Reviewed
May 1, 2023
Last updated
Nov 7, 2023
Impact
Possible prototype pollution for the
MetadataRecord
, when merged with a base class' metadata object, inmeta
decorator from the@aedart/support
package.The likelihood is questionable, given that a class' metadata can only be set or altered when the class is decorated via
meta()
. Furthermore, object(s) of sensitive nature would have to be stored as metadata, before this can become a vulnerability.Patches
Has been patched in version
0.6.1
.References