secdevlpr26

Results 15 issues of secdevlpr26

Prototype pollution vulnerability in function extend in babel.js in stealjs steal 2.2.4 via the key variable in babel.js. The prototype pollution vulnerability can be mitigated with several best practices described...

Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js. The prototype pollution vulnerability can be mitigated with several best practices described here: https://learn.snyk.io/lessons/prototype-pollution/javascript/

Prototype pollution vulnerability in stealjs steal 2.2.4 via the optionName variable in main.js. The prototype pollution vulnerability can be mitigated with several best practices described here: https://learn.snyk.io/lessons/prototype-pollution/javascript/

A Regular expression denial of service (ReDoS) flaw was found in Function win32 in babel.js in stealjs steal 2.2.4 via the path variable in babel.js. The ReDoS vulnerability can be...

A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the source and sourceWithComments variable in main.js. The ReDoS vulnerability can be mitigated with several...

Prototype pollution vulnerability in function addNpmExtension in npm-extension.js in stealjs steal 2.3.0-pre.0 via the name variable in npm-extension.js. The prototype pollution vulnerability can be mitigated with several best practices described...

A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the input variable in main.js. The ReDoS vulnerability can be mitigated with several best practices...

A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the string variable in babel.js. The ReDoS vulnerability can be mitigated with several best practices...

Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName variable in npm-convert.js. The prototype pollution vulnerability can be mitigated with several best practices described...

Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js. The prototype pollution vulnerability can be mitigated with several best practices described...