Headline
GHSA-45rm-2893-5f49: liquidjs may leak properties of a prototype
The package liquidjs before 10.0.0 is vulnerable to Information Exposure when ownPropertyOnly
parameter is set to False
, which results in leaking properties of a prototype. Workaround For versions 9.34.0 and higher, an option to disable this functionality is provided.
liquidjs may leak properties of a prototype
Moderate severity GitHub Reviewed Published Dec 22, 2022 • Updated Dec 22, 2022
Related news
CVE-2022-25948: feat: `ownPropertyOnly` option to protect prototype, #454 · harttle/liquidjs@7e99efc
The package liquidjs before 10.0.0 are vulnerable to Information Exposure when ownPropertyOnly parameter is set to False, which results in leaking properties of a prototype. Workaround For versions 9.34.0 and higher, an option to disable this functionality is provided.