PT-2021-15488 · Nedb · Nedb

Published

2021-06-15

·

Updated

2023-08-08

·

CVE-2021-23395

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions nedb versions all
Description The library could be tricked into adding or modifying properties of Object.prototype using a proto or constructor.prototype payload. This issue affects all versions of the package.
Recommendations For all versions, consider restricting the use of the library until a patch is available, or apply configuration changes to prevent the manipulation of Object.prototype properties. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2021-23395
GHSA-339J-HQGX-QRRX

Affected Products

Nedb