PT-2021-15509 · Unknown · Merge-Change

Dung Le

·

Published

2021-08-11

·

Updated

2021-09-01

·

CVE-2021-23421

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions merge-change versions all
Description The issue concerns Prototype Pollution via the utils.set function. This affects all versions of the package merge-change.
Recommendations For all versions, consider disabling the utils.set function as a temporary workaround until a patch is available. Restrict access to the vulnerable function to minimize the risk of exploitation. Avoid using the utils.set function in sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23421
GHSA-F9CV-665R-275H

Affected Products

Merge-Change