{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-05T06:35:57.087","vulnerabilities":[{"cve":{"id":"CVE-2020-7765","sourceIdentifier":"report@snyk.io","published":"2020-11-16T12:15:14.320","lastModified":"2026-06-17T03:25:24.407","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"This affects the package @firebase/util before 0.3.4. This vulnerability relates to the deepExtend function within the DeepCopy.ts file. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program."},{"lang":"es","value":"Esto afecta al paquete @firebase/util versiones anteriores a 0.3.4.&#xa0;Esta vulnerabilidad se relaciona con la función deepExtend dentro del archivo DeepCopy.ts.&#xa0;Dependiendo de si se proporciona la entrada del usuario, un atacante puede sobrescribir y contaminar el prototipo de objeto de un programa"}],"affected":[{"source":"report@snyk.io","affectedData":[{"vendor":"n/a","product":"@firebase/util","versions":[{"version":"unspecified","lessThan":"0.3.4","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"report@snyk.io","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","baseScore":5.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.2,"impactScore":3.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:google:firebase\\/util:*:*:*:*:*:node.js:*:*","versionEndExcluding":"0.3.4","matchCriteriaId":"D314A889-D332-4B9B-AB10-89B8F2D600D9"}]}]}],"references":[{"url":"https://github.com/firebase/firebase-js-sdk/commit/9cf727fcc3d049551b16ae0698ac33dc2fe45ada","source":"report@snyk.io","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/firebase/firebase-js-sdk/pull/4001","source":"report@snyk.io","tags":["Patch","Third Party Advisory"]},{"url":"https://snyk.io/vuln/SNYK-JS-FIREBASEUTIL-1038324","source":"report@snyk.io","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/firebase/firebase-js-sdk/commit/9cf727fcc3d049551b16ae0698ac33dc2fe45ada","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/firebase/firebase-js-sdk/pull/4001","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://snyk.io/vuln/SNYK-JS-FIREBASEUTIL-1038324","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}}]}