PT-2021-17969 · Npm · Node.Js Mixme
Cyber-Dude1
·
Published
2021-05-03
·
Updated
2024-02-14
·
CVE-2021-28860
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Node.js mixme versions prior to 0.5.1
Description:
The issue allows an attacker to add or alter properties of an object via
proto through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program, putting the availability of the program at risk and causing a potential denial of service (DoS).Recommendations:
For versions prior to 0.5.1, update to version 0.5.1 or later to resolve the issue.
As a temporary workaround, consider disabling the
mutate() and merge() functions until a patch is available.Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Node.Js Mixme