CVE-2020-28503: Prototype Pollution
Published Mar 23, 2021
·Updated
The package copy-props before 2.0.5 are vulnerable to Prototype Pollution via the main functionality.
Affected Software
1 affected component
gulpjs Copy-props Node.js<2.0.5
Remediation
Patch Available
Event History
Mar 23, 2021
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-28503?
CVE-2020-28503 is a vulnerability that affects the package copy-props before version 2.0.5.
2
How severe is CVE-2020-28503?
CVE-2020-28503 has a severity rating of 9.8 (critical).
3
How does CVE-2020-28503 impact the affected software?
CVE-2020-28503 allows for Prototype Pollution via the main functionality of the copy-props package.
4
Which software versions are affected by CVE-2020-28503?
The copy-props package versions before 2.0.5 are affected by CVE-2020-28503.
5
Is there a fix available for CVE-2020-28503?
Yes, updating the copy-props package to version 2.0.5 or later will fix CVE-2020-28503.