Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks.
The product does not properly protect an assumed-immutable element from being modified by an attacker.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Typeorm | Typeorm | * | 0.2.25 (excluding) |