PT-2024-28314 · Requirejs+4 · Requirejs+4

Mestrtee

·

Published

2024-07-01

·

Updated

2026-03-15

·

CVE-2024-38999

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions requirejs version 2.3.6
Description The issue is related to a prototype pollution vulnerability via the function s.contexts. .configure. This allows attackers to execute arbitrary code or cause a Denial of Service (DoS) by injecting arbitrary properties.
Recommendations For version 2.3.6, consider disabling the s.contexts. .configure function as a temporary workaround until a patch is available. Restrict access to the configure function within the s.contexts. context to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Prototype Pollution

Weakness Enumeration

Related Identifiers

ALT-PU-2025-6924
ALT-PU-2025-7344
BDU:2025-04328
CVE-2024-38999
GHSA-X3M3-4WPV-5VGC
OESA-2026-1600
OPENSUSE-SU-2024_3771-1
SUSE-SU-2024:3771-1

Affected Products

Alt Linux
Bitbucket
Debian
Suse
Requirejs