PT-2021-18252 · Mixme · Mixme

Published

2021-06-22

·

Updated

2022-03-14

·

CVE-2021-29491

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions: mixme version 0.5.0
Description: The issue allows an attacker to add or alter properties of an object via proto through the mutate() and merge() functions, potentially causing a denial of service (DoS) and putting the program's availability at risk.
Recommendations: For mixme version 0.5.0, update to version 0.5.1 or later to resolve the issue. As a temporary workaround, consider disabling the mutate() and merge() functions until a patch is available. Restrict access to the proto property to minimize the risk of exploitation.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-29491

Affected Products

Mixme