PT-2022-9425 · Keyget · Keyget

Cristian-Alexandru Staicu

+1

·

Published

2022-01-28

·

Updated

2022-02-04

·

CVE-2021-23760

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions keyget versions 0.0.0 and later
Description The issue allows an attacker to cause a denial of service and may lead to remote code execution via Prototype Pollution. This is possible through the methods set, push, and at.
Recommendations For keyget versions 0.0.0 and later, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23760
GHSA-9FP7-4FJM-Q3MF

Affected Products

Keyget