Minimist <= 1.2.5 - Prototype Pollution

2022-03-18 00:00
Anonymous

Strategic Overview

Status
Patched in 1.2.1
Affected PluginConvert to Blocks
Affected Version<= 1.2.0
CVSS9.8Critical
CVEN/A
View all Convert to Blocks vulnerabilities

Vulnerability Overview

Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95). Fixed in 1.2.6. Some WordPress plugins and themes use this dependency though that doesn’t necessarily mean the plugin itself is vulnerable to exploitation.

Technical Analysis

REMEDIATION: Update to version 1.2.1, or a newer patched version --- IDENTIFIER: CWE-915 (Improperly Controlled Modification of Dynamically-Determined Object Attributes) The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C