Candidate: CVE-2018-16472 PublicDate: 2018-11-06 19:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16472 https://hackerone.com/reports/390847 Description: A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects through the prototype chain causing a DoS attack. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_node-cached-path-relative: upstream_node-cached-path-relative: released (1.2.0) precise/esm_node-cached-path-relative: DNE trusty_node-cached-path-relative: DNE trusty/esm_node-cached-path-relative: DNE xenial_node-cached-path-relative: DNE bionic_node-cached-path-relative: needed cosmic_node-cached-path-relative: ignored (reached end-of-life) disco_node-cached-path-relative: ignored (reached end-of-life) eoan_node-cached-path-relative: not-affected (1.0.2-1) focal_node-cached-path-relative: not-affected (1.0.2-1) groovy_node-cached-path-relative: not-affected (1.0.2-1) hirsute_node-cached-path-relative: not-affected (1.0.2-1) impish_node-cached-path-relative: not-affected (1.0.2-1) jammy_node-cached-path-relative: not-affected (1.0.2-1) devel_node-cached-path-relative: not-affected (1.0.2-1)