From eb69ceaae88e38a0ab729cd2aa5e0fe84edfd021 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 1 Apr 2025 14:34:16 +0000 Subject: [PATCH] Publish GHSA-799q-f2px-wx8c --- .../03/GHSA-799q-f2px-wx8c/GHSA-799q-f2px-wx8c.json | 11 +++++------ 1 file changed, 5 insertions(+), 6 deletions(-) diff --git a/advisories/github-reviewed/2025/03/GHSA-799q-f2px-wx8c/GHSA-799q-f2px-wx8c.json b/advisories/github-reviewed/2025/03/GHSA-799q-f2px-wx8c/GHSA-799q-f2px-wx8c.json index 1941d499c37..7292ef473e6 100644 --- a/advisories/github-reviewed/2025/03/GHSA-799q-f2px-wx8c/GHSA-799q-f2px-wx8c.json +++ b/advisories/github-reviewed/2025/03/GHSA-799q-f2px-wx8c/GHSA-799q-f2px-wx8c.json @@ -1,13 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-799q-f2px-wx8c", - "modified": "2025-03-31T15:57:16Z", + "modified": "2025-04-01T14:32:14Z", "published": "2025-03-28T21:30:46Z", - "aliases": [ - "CVE-2024-38988" - ], - "summary": "@alizeait/unflatto Prototype Pollution via `exports.unflatto` Method", - "details": "alizeait unflatto <= 1.0.2 was discovered to contain a prototype pollution via the method exports.unflatto at /dist/index.js. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.", + "withdrawn": "2025-04-01T14:32:14Z", + "aliases": [], + "summary": "Duplicate Advisory: @alizeait/unflatto Prototype Pollution via `exports.unflatto` Method", + "details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-q8jq-4rm5-4hm5. This link is maintained to preserve external references.\n\n## Original Description\nalizeait unflatto <= 1.0.2 was discovered to contain a prototype pollution via the method exports.unflatto at /dist/index.js. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.", "severity": [ { "type": "CVSS_V4",