PT-2024-18905 · Uplot · Uplot

Tariq Hawis

·

Published

2024-09-30

·

Updated

2024-10-06

·

CVE-2024-21489

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions uplot versions prior to 1.6.31
Description The issue is related to Prototype Pollution via the uplot.assign function due to a missing check if the attribute resolves to the object prototype. This allows for potential manipulation of the object's prototype, leading to security issues.
Recommendations For versions prior to 1.6.31, update to version 1.6.31 or later to resolve the issue. As a temporary workaround, consider disabling the uplot.assign function until a patch is available.

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2024-21489
GHSA-34Q8-JCQ6-MC37
RHSA-2024:8083

Affected Products

Uplot