PT-2021-17969 · Npm · Node.Js Mixme

Cyber-Dude1

·

Published

2021-05-03

·

Updated

2024-02-14

·

CVE-2021-28860

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Node.js mixme versions prior to 0.5.1
Description: The issue allows an attacker to add or alter properties of an object via proto through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program, putting the availability of the program at risk and causing a potential denial of service (DoS).
Recommendations: For versions prior to 0.5.1, update to version 0.5.1 or later to resolve the issue. As a temporary workaround, consider disabling the mutate() and merge() functions until a patch is available.

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2021-28860
GHSA-79JW-6WG7-R9G4
GHSA-R5CQ-9537-9RPF

Affected Products

Node.Js Mixme