substack records
2 published records for vendor substack.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Attack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2021-44906Proof of concept | Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).substack · minimist · CWE-1321 | Critical9.8 | — | 4.6% | Mar 17, 2022 |
23Monitor | CVE-2020-7598Proof of concept | minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.substack · minimist · CWE-1321 | Medium5.6 | — | 1.9% | Mar 11, 2020 |
- CVE-2021-4490640Plan
Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
CriticalCVSS 9.8Proof of conceptEPSS 5%substack · minimistMar 17, 2022
- CVE-2020-759823Monitor
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
MediumCVSS 5.6Proof of conceptEPSS 2%substack · minimistMar 11, 2020