Minimist <= 1.2.5 - Prototype Pollution
2022-03-18 00:00
AnonymousStrategic Overview
Vulnerability Overview
Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95). Fixed in 1.2.6. Some WordPress plugins and themes use this dependency though that doesn’t necessarily mean the plugin itself is vulnerable to exploitation.
Technical Analysis
REMEDIATION: Update to version 1.2.1, or a newer patched version --- IDENTIFIER: CWE-915 (Improperly Controlled Modification of Dynamically-Determined Object Attributes) The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C