PT-2025-5757 · Unknown · Underscore-Contrib

Published

2025-02-05

·

Updated

2025-02-06

·

CVE-2024-57081

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: underscore-contrib version 0.3.0
Description: A prototype pollution in the lib.fromQuery function allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
Recommendations: For underscore-contrib version 0.3.0, consider disabling the lib.fromQuery function until a patch is available to prevent potential Denial of Service (DoS) attacks.

Fix

DoS

Resource Exhaustion

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-57081

Affected Products

Underscore-Contrib