Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Steal
(Stealjs)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 8 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2022-09-20 | CVE-2022-37259 | A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the string variable in babel.js. | Steal | 7.5 | ||
2022-09-20 | CVE-2022-37265 | Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js. | Steal | 9.8 | ||
2022-09-15 | CVE-2022-37257 | Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js. | Steal | 9.8 | ||
2022-09-15 | CVE-2022-37266 | Prototype pollution vulnerability in function extend in babel.js in stealjs steal 2.2.4 via the key variable in babel.js. | Steal | 9.8 | ||
2022-09-15 | CVE-2022-37262 | A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the source and sourceWithComments variable in main.js. | Steal | 7.5 | ||
2022-09-15 | CVE-2022-37264 | Prototype pollution vulnerability in stealjs steal 2.2.4 via the optionName variable in main.js. | Steal | 9.8 | ||
2022-09-15 | CVE-2022-37260 | A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the input variable in main.js. | Steal | 7.5 | ||
2022-09-16 | CVE-2022-37258 | Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName variable in npm-convert.js. | Steal | 9.8 |