{"id":"CVE-2024-23339","aliases":[],"url":"https://o3.security/vulnerability/CVE-2024-23339","summary":"hoolock is a suite of lightweight utilities designed to maintain a small footprint when bundled. Starting in version 2.0.0 and prior to version 2.2.1, utility functions related to object…","details":"hoolock is a suite of lightweight utilities designed to maintain a small footprint when bundled. Starting in version 2.0.0 and prior to version 2.2.1, utility functions related to object paths (`get`, `set`, and `update`) did not block attempts to access or alter object prototypes. Starting in version 2.2.1, the `get`, `set` and `update` functions throw a `TypeError` when a user attempts to access or alter inherited properties.","published":"2024-01-22T22:54:53.096Z","modified":"2025-06-17T21:19:25.952Z","cvss":{"score":6.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":{"url":"https://github.com/elijahharry/hoolock/commit/97ae80e856774335d92743c635ffeae2f652b982","label":"elijahharry/hoolock@97ae80e"},"references":[{"type":"WEB","url":"https://github.com/elijahharry/hoolock/security/advisories/GHSA-4c2g-hx49-7h25"},{"type":"WEB","url":"https://github.com/elijahharry/hoolock/commit/97ae80e856774335d92743c635ffeae2f652b982"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2025-06-17T21:19:25.952Z"}}