VYPR

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

VariantIncomplete

Description

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-180 · CAPEC-77

CVEs mapped to this weakness (612)

page 19 of 31
  • CVE-2024-45815MedSep 17, 2024
    risk 0.42cvss 6.5epss 0.01

    Backstage is an open framework for building developer portals. A malicious actor with authenticated access to a Backstage instance with the catalog backend plugin installed is able to interrupt the service using a specially crafted query to the catalog API. This has been fixed…

  • CVE-2024-39853MedJul 1, 2024
    risk 0.42cvss 6.5epss 0.01

    adolph_dudu ratio-swiper 0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-39000MedJul 1, 2024
    risk 0.42cvss 6.5epss 0.00

    adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-38997MedJul 1, 2024
    risk 0.42cvss 6.5epss 0.00

    adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function extendDefaults. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-21505HigMar 25, 2024
    risk 0.42cvss 7.5epss 0.01

    Versions of the package web3-utils before 4.2.1 are vulnerable to Prototype Pollution via the utility functions format and mergeDeep, due to insecure recursive merge. An attacker can manipulate an object's prototype, potentially leading to the alteration of the behavior of all…

  • CVE-2023-45282HigOct 6, 2023
    risk 0.42cvss 7.5epss 0.01

    In NASA Open MCT (aka openmct) before 3.1.0, prototype pollution can occur via an import action.

  • CVE-2023-26132HigJun 10, 2023
    risk 0.42cvss 7.5epss 0.01

    Versions of the package dottie before 2.0.4 are vulnerable to Prototype Pollution due to insufficient checks, via the set() function and the current variable in the /dottie.js file.

  • CVE-2023-26113HigMar 18, 2023
    risk 0.42cvss 7.5epss 0.01

    Versions of the package collection.js before 6.8.1 are vulnerable to Prototype Pollution via the extend function in Collection.js/dist/node/iterators/extend.js.

  • CVE-2022-25907HigAug 9, 2022
    risk 0.42cvss 7.5epss 0.02

    The package ts-deepmerge before 2.0.2 are vulnerable to Prototype Pollution due to missing sanitization of the merge function.

  • CVE-2022-21213HigJun 17, 2022
    risk 0.42cvss 7.5epss 0.02

    This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn mixes objects into the target object, recursively mixing existing child objects as well. In both cases, the key used to access the target…

  • CVE-2022-21190HigMay 13, 2022
    risk 0.42cvss 7.5epss 0.04

    This affects the package convict before 6.2.3. This is a bypass of [CVE-2022-22143](https://security.snyk.io/vuln/SNYK-JS-CONVICT-2340604). The [fix](https://github.com/mozilla/node-convict/commit/3b86be087d8f14681a9c889d45da7fe3ad9cd880) introduced, relies on the startsWith…

  • CVE-2022-22143HigMay 1, 2022
    risk 0.42cvss 7.5epss 0.02

    The package convict before 6.2.2 are vulnerable to Prototype Pollution via the convict function due to missing validation of parentKey. **Note:** This vulnerability derives from an incomplete fix of another [vulnerability](https://security.snyk.io/vuln/SNYK-JS-CONVICT-1062508)

  • CVE-2022-24279HigApr 15, 2022
    risk 0.42cvss 7.5epss 0.01

    The package madlib-object-utils before 0.1.8 are vulnerable to Prototype Pollution via the setValue method, as it allows an attacker to merge object prototypes into it. *Note:* This vulnerability derives from an incomplete fix of [CVE-2020-7701](https://security.snyk.io/vuln/SNYK…

  • CVE-2022-25352HigMar 17, 2022
    risk 0.42cvss 7.5epss 0.02

    The package libnested before 1.5.2 are vulnerable to Prototype Pollution via the set function in index.js. **Note:** This vulnerability derives from an incomplete fix for [CVE-2020-28283](https://security.snyk.io/vuln/SNYK-JS-LIBNESTED-1054930)

  • CVE-2021-23771MedMar 17, 2022
    risk 0.42cvss 6.5epss 0.01

    This affects all versions of package notevil; all versions of package argencoders-notevil. It is vulnerable to Sandbox Escape leading to Prototype pollution. The package fails to restrict access to the main context, allowing an attacker to add or modify an object's prototype.…

  • CVE-2021-23597HigFeb 11, 2022
    risk 0.42cvss 7.5epss 0.02

    This affects the package fastify-multipart before 5.3.1. By providing a name=constructor property it is still possible to crash the application. **Note:** This is a bypass of CVE-2020-8136 (https://security.snyk.io/vuln/SNYK-JS-FASTIFYMULTIPART-1290382).

  • CVE-2021-23507HigFeb 4, 2022
    risk 0.42cvss 7.5epss 0.02

    The package object-path-set before 1.0.2 are vulnerable to Prototype Pollution via the setPath method, as it allows an attacker to merge object prototypes into it. *Note:* This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-OBJECTPATHSET-607…

  • CVE-2021-23497HigFeb 4, 2022
    risk 0.42cvss 7.5epss 0.04

    This affects the package @strikeentco/set before 1.0.2. It allows an attacker to cause a denial of service and may lead to remote code execution. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-STRIKEENTCOSET-1038821

  • CVE-2021-23460HigJan 21, 2022
    risk 0.42cvss 7.5epss 0.02

    The package min-dash before 3.8.1 are vulnerable to Prototype Pollution via the set method due to missing enforcement of key types.

  • CVE-2021-23700MedDec 10, 2021
    risk 0.42cvss 6.5epss 0.01

    All versions of package merge-deep2 are vulnerable to Prototype Pollution via the mergeDeep() function.