Severity
9.8CRITICALNVD
CNA7.3
EPSS
0.5%
top 35.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 17
Latest updateSep 4

Description

The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages6 packages

CVEListV5y18n_project/y18nunspecified5.0.5
NVDy18n_project/y18n5.0.05.0.5+2
npmy18n_project/y18n4.0.04.0.1+2
NVDoracle/graalvm19.3.5, 20.3.1.2, 21.0.0.2+2

Patches

🔴Vulnerability Details

4
OSV
Prototype Pollution in y18n2021-03-29
GHSA
Prototype Pollution in y18n2021-03-29
CVEList
Prototype Pollution2020-11-17
OSV
CVE-2020-7774: The package y18n before 32020-11-17

📋Vendor Advisories

3
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS2024-09-04
Red Hat
nodejs-y18n: prototype pollution vulnerability2020-10-25
Debian
CVE-2020-7774: node-y18n - The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollu...2020
CVE-2020-7774 — Prototype Pollution in Project Y18n | cvebase