You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Prototype Pollution in node-forge util.setPath API
Low severity
GitHub Reviewed
Published
Jan 6, 2022
in
digitalbazaar/forge
•
Updated Jan 11, 2023
Impact
forge.util.setPath
had a potential prototype pollution issue if called with untrusted keys. This API was not used by forge itself.Patches
The
forge.util.setPath
API and related functions were removed in 0.10.0.Workarounds
Don't call
forge.util.setPath
directly or indirectly with untrusted keys.References
For more information
If you have any questions or comments about this advisory:
References