math.js Improperly Controlled Modification of Dynamically-Determined Object Attributes Vulnerability - CVE-2020-7743 - Vulnerability Database
math.js Improperly Controlled Modification of Dynamically-Determined Object Attributes Vulnerability - CVE-2020-7743
High
Reference:
CVE-2020-7743
Title:
math.js Improperly Controlled Modification of Dynamically-Determined Object Attributes Vulnerability
Overview:
The package mathjs before 7.5.1 are vulnerable to Prototype Pollution via the deepExtend function that runs upon configuration updates.