PT-2022-9415 · Extend2 · Extend2

Bob Wombat Hogg

·

Published

2022-01-07

·

Updated

2022-01-13

·

CVE-2021-23568

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions extend2 versions prior to 1.0.1
Description The issue concerns Prototype Pollution via the extend function due to an unsafe recursive merge. This allows for potential manipulation of the prototype, which can lead to various security issues.
Recommendations For versions prior to 1.0.1, update to version 1.0.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the extend function until a patch is applied.

Exploit

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23568
GHSA-GJM5-83CW-P3P2
SNYK-JS-EXTEND2-2320315

Affected Products

Extend2