CVE-2021-21304
Description
Dynamoose is an open-source modeling tool for Amazon's DynamoDB. In Dynamoose from version 2.0.0 and before version 2.7.0 there was a prototype pollution vulnerability in the internal utility method "lib/utils/object/set.ts". This method is used throughout the codebase for various operations throughout Dynamoose. We have not seen any evidence of this vulnerability being exploited. There is no evidence this vulnerability impacts versions 1.x.x since the vulnerable method was added as part of the v2 rewrite. This vulnerability also impacts v2.x.x beta/alpha versions. Version 2.7.0 includes a patch for this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dynamoosenpm | >= 2.0.0, < 2.7.0 | 2.7.0 |
Affected products
3Patches
Vulnerability mechanics
References
6- github.com/dynamoose/dynamoose/commit/324c62b4709204955931a187362f8999805b1d8envdPatchThird Party AdvisoryWEB
- github.com/dynamoose/dynamoose/security/advisories/GHSA-rrqm-p222-8ph2nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-rrqm-p222-8ph2ghsaADVISORY
- github.com/dynamoose/dynamoose/releases/tag/v2.7.0nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-21304ghsaADVISORY
- www.npmjs.com/package/dynamoosenvdProductThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.