Candidate: CVE-2018-3719 PublicDate: 2018-06-07 02:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3719 https://nodesecurity.io/advisories/578 Description: mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=898315 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_node-mixin-deep: upstream_node-mixin-deep: needs-triage precise/esm_node-mixin-deep: DNE trusty_node-mixin-deep: DNE trusty/esm_node-mixin-deep: DNE xenial_node-mixin-deep: DNE artful_node-mixin-deep: ignored (reached end-of-life) bionic_node-mixin-deep: needs-triage cosmic_node-mixin-deep: ignored (reached end-of-life) disco_node-mixin-deep: ignored (reached end-of-life) eoan_node-mixin-deep: ignored (reached end-of-life) focal_node-mixin-deep: needs-triage groovy_node-mixin-deep: ignored (reached end-of-life) hirsute_node-mixin-deep: ignored (reached end-of-life) impish_node-mixin-deep: needs-triage jammy_node-mixin-deep: needs-triage devel_node-mixin-deep: needs-triage