CVE-2019-10798

MEDIUM

rdf-graph-array <= 0.3.0-rc6 - Prototype Pollution via Graph Add Method

Title source: llm
STIX 2.1

Description

rdf-graph-array through 0.3.0-rc6 manipulation of JavaScript objects resutling in Prototype Pollution. The rdf.Graph.prototype.add method could be tricked into adding or modifying properties of Object.prototype.

References (2)

Core 2

Scores

CVSS v3 5.3
EPSS 0.0107
EPSS Percentile 61.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

Status published
Products (2)
npm/rdf-graph-array 0npm
rdf-graph-array_project/rdf-graph-array 0.3.0 (3 CPE variants)
Published Feb 24, 2020
Tracked Since Feb 18, 2026