PT-2022-9412 · Bmoor · Bmoor

Cristian-Alexandru Staicu

+2

·

Published

2022-01-28

·

Updated

2022-02-04

·

CVE-2021-23558

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions bmoor versions prior to 0.10.1
Description The issue is related to Prototype Pollution due to missing sanitization in the set function. This problem arises from an incomplete fix.
Recommendations For versions prior to 0.10.1, update to version 0.10.1 or later to resolve the issue. As a temporary workaround, consider disabling the set function until a patch is available. Restrict access to the set function to minimize the risk of exploitation.

Exploit

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23558
GHSA-4M8H-H59M-M34J
SNYK-JS-BMOOR-2342622

Affected Products

Bmoor