PT-2025-5751 · Xe-Utils · Xe-Utils

Published

2025-02-05

·

Updated

2025-02-06

·

CVE-2024-57074

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: xe-utils version 3.5.31
Description: A prototype pollution in the lib.merge function allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
Recommendations: For version 3.5.31, consider disabling the lib.merge function as a temporary workaround until a patch is available. Restrict access to the lib.merge function to minimize the risk of exploitation. Avoid using the lib.merge function in sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Resource Exhaustion

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2024-57074

Affected Products

Xe-Utils