This affects the package com.graphhopper:graphhopper-web-bundle before 3.2, from 4.0-pre1 and before 4.0. The URL parser could be tricked into adding or modifying properties of Object.prototype using a constructor or __proto__ payload.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.graphhopper:graphhopper-web-bundle(Maven) | 0 | 3.2 | N/A |
CVSS Metrics