296,224
Total vulnerabilities in the database
In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution.
Software | From | Fixed in |
---|---|---|
async_project / async | - | 2.6.4 |
async_project / async | 3.0.0 | 3.2.2 |
fedoraproject / fedora | 36 | 36.x |
fedoraproject / fedora | 37 | 37.x |
![]() |
3.0.0 | 3.2.2 |
![]() |
2.0.0 | 2.6.4 |