High severity7.5NVD Advisory· Published Dec 24, 2021· Updated Jun 17, 2026
CVE-2021-23574
CVE-2021-23574
Description
All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn and the set functions. This is an incomplete fix of CVE-2020-28442.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
js-datanpm | <= 3.0.10 | — |
Affected products
3- js-data/js-datadescription
Patches
Vulnerability mechanics
References
8- github.com/js-data/js-data/issues/576nvdIssue TrackingPatchThird Party AdvisoryWEB
- github.com/js-data/js-data/issues/577nvdIssue TrackingPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-2320790nvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2320791nvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-JSDATA-1584361nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-c6h4-gc3f-hgjqghsaADVISORY
- github.com/js-data/js-data/blob/master/dist/js-data.js%23L472nvdBroken LinkThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-23574ghsaADVISORY
News mentions
0No linked articles in our index yet.