PT-2021-15507 · Unknown · Open-Graph

Published

2021-08-08

·

Updated

2024-01-31

·

CVE-2021-23419

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions open-graph versions prior to 0.2.6
Description The issue affects the parse function, which can be tricked into adding or modifying properties of Object.prototype using a proto or constructor payload. This could potentially lead to unintended behavior or security issues.
Recommendations For versions prior to 0.2.6, update to version 0.2.6 or later to resolve the issue. As a temporary workaround, consider restricting the use of the parse function until a patch is available.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2021-23419
GHSA-G452-6RFC-VRVX
SNYK-JS-OPENGRAPH-1536747

Affected Products

Open-Graph