PT-2022-9426 · Notevil+1 · Notevil+1

Abdullah Alhamdan

+1

·

Published

2022-03-17

·

Updated

2022-03-24

·

CVE-2021-23771

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions notevil versions all argencoders-notevil versions all
Description The issue is related to Sandbox Escape leading to Prototype pollution. The package fails to restrict access to the main context, allowing an attacker to add or modify an object's prototype. This vulnerability derives from an incomplete fix. The package notevil and its variant argencoders-notevil have been affected, with the latter being deprecated.
Recommendations For notevil all versions, consider restricting access to the main context to prevent prototype pollution. For argencoders-notevil all versions, as the package is deprecated, it is recommended to avoid using it and consider alternative solutions to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23771
GHSA-8G4M-CJM2-96WQ
SNYK-JS-ARGENCODERSNOTEVIL-2388587
SNYK-JS-NOTEVIL-2385946

Affected Products

Argencoders-Notevil
Notevil