mpath
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting mpathpage 1 of 1
- CVE-2018-16490HIGHCVSS 7.5EG 7.5✓ Fixed in 0.5.12019-02-01
A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary properties onto Object.prototype.
- CVE-2021-23438MEDIUMCVSS 5.6EG 5.6✓ Fixed in 0.8.42021-09-01
This affects the package mpath before 0.8.4. A type confusion vulnerability can lead to a bypass of CVE-2018-16490. In particular, the condition ignoreProperties.indexOf(parts[i]) !== -1 returns -1 if parts[i] is ['__proto__']. This is bec…
Check whether mpath is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for mpath CVEs against the assets you own.
Start Free Scan →