CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Description
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-180 · CAPEC-77
CVEs mapped to this weakness (612)
page 2 of 31| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-39010 | Cri | 0.64 | 9.8 | 0.01 | Jul 30, 2024 | chase-moskal snapstate v0.0.9 was discovered to contain a prototype pollution via the function attemptNestedProperty. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties. | ||
| CVE-2024-38984 | Cri | 0.64 | 9.8 | 0.01 | Jul 30, 2024 | Prototype Pollution in lukebond json-override 0.2.0 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via the __proto__ property. | ||
| CVE-2024-36572 | Cri | 0.64 | 9.8 | 0.01 | Jul 30, 2024 | Prototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the functions setDefaults, mergeBranch, and Object.setObjectValue. | ||
| CVE-2024-39014 | Cri | 0.64 | 9.8 | 0.01 | Jul 1, 2024 | ahilfoley cahil/utils v2.3.2 was discovered to contain a prototype pollution via the function set. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties. | ||
| CVE-2024-39013 | Cri | 0.64 | 9.8 | 0.01 | Jul 1, 2024 | 2o3t-utility v0.1.2 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties. | ||
| CVE-2024-38993 | Cri | 0.64 | 9.8 | 0.01 | Jul 1, 2024 | rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties. | ||
| CVE-2024-36582 | — | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2024 | alexbinary object-deep-assign 1.0.11 is vulnerable to Prototype Pollution via the extend() method of Module.deepAssign (/src/index.js) | |
| CVE-2024-36580 | — | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2024 | A Prototype Pollution issue in cdr0 sg 1.0.10 allows an attacker to execute arbitrary code. | |
| CVE-2022-37598 | Cri | 0.64 | 9.8 | 0.01 | Oct 20, 2022 | Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.js. NOTE: the vendor considers this an invalid report. | ||
| CVE-2022-37602 | Cri | 0.64 | 9.8 | 0.02 | Oct 14, 2022 | Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js. | ||
| CVE-2022-37614 | Cri | 0.64 | 9.8 | 0.01 | Oct 12, 2022 | Prototype pollution vulnerability in function enable in mockery.js in mfncooper mockery commit 822f0566fd6d72af8c943ae5ca2aa92e516aa2cf via the key variable in mockery.js. | ||
| CVE-2022-37609 | Cri | 0.64 | 9.8 | 0.01 | Oct 11, 2022 | Prototype pollution vulnerability in beautify-web js-beautify 1.13.7 via the name variable in options.js. | ||
| CVE-2022-37265 | Cri | 0.64 | 9.8 | 0.01 | Sep 20, 2022 | Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js. | ||
| CVE-2022-37258 | Cri | 0.64 | 9.8 | 0.01 | Sep 16, 2022 | Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName variable in npm-convert.js. | ||
| CVE-2022-37264 | Cri | 0.64 | 9.8 | 0.01 | Sep 15, 2022 | Prototype pollution vulnerability in stealjs steal 2.2.4 via the optionName variable in main.js. | ||
| CVE-2022-37266 | Cri | 0.64 | 9.8 | 0.01 | Sep 15, 2022 | Prototype pollution vulnerability in function extend in babel.js in stealjs steal 2.2.4 via the key variable in babel.js. | ||
| CVE-2022-37257 | Cri | 0.64 | 9.8 | 0.01 | Sep 15, 2022 | Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js. | ||
| CVE-2021-40663 | Cri | 0.64 | 9.8 | 0.02 | Jun 30, 2022 | deep.assign npm package 0.0.0-alpha.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'). | ||
| CVE-2021-23594 | Cri | 0.64 | 9.8 | 0.02 | Jan 10, 2022 | All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector. | ||
| CVE-2021-23543 | Cri | 0.64 | 9.8 | 0.02 | Jan 10, 2022 | All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector. |
- risk 0.64cvss 9.8epss 0.01
chase-moskal snapstate v0.0.9 was discovered to contain a prototype pollution via the function attemptNestedProperty. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
- risk 0.64cvss 9.8epss 0.01
Prototype Pollution in lukebond json-override 0.2.0 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via the __proto__ property.
- risk 0.64cvss 9.8epss 0.01
Prototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the functions setDefaults, mergeBranch, and Object.setObjectValue.
- risk 0.64cvss 9.8epss 0.01
ahilfoley cahil/utils v2.3.2 was discovered to contain a prototype pollution via the function set. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
- risk 0.64cvss 9.8epss 0.01
2o3t-utility v0.1.2 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
- risk 0.64cvss 9.8epss 0.01
rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
- risk 0.64cvss 9.8epss 0.01
alexbinary object-deep-assign 1.0.11 is vulnerable to Prototype Pollution via the extend() method of Module.deepAssign (/src/index.js)
- risk 0.64cvss 9.8epss 0.01
A Prototype Pollution issue in cdr0 sg 1.0.10 allows an attacker to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.js. NOTE: the vendor considers this an invalid report.
- risk 0.64cvss 9.8epss 0.02
Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js.
- risk 0.64cvss 9.8epss 0.01
Prototype pollution vulnerability in function enable in mockery.js in mfncooper mockery commit 822f0566fd6d72af8c943ae5ca2aa92e516aa2cf via the key variable in mockery.js.
- risk 0.64cvss 9.8epss 0.01
Prototype pollution vulnerability in beautify-web js-beautify 1.13.7 via the name variable in options.js.
- risk 0.64cvss 9.8epss 0.01
Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js.
- risk 0.64cvss 9.8epss 0.01
Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName variable in npm-convert.js.
- risk 0.64cvss 9.8epss 0.01
Prototype pollution vulnerability in stealjs steal 2.2.4 via the optionName variable in main.js.
- risk 0.64cvss 9.8epss 0.01
Prototype pollution vulnerability in function extend in babel.js in stealjs steal 2.2.4 via the key variable in babel.js.
- risk 0.64cvss 9.8epss 0.01
Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js.
- risk 0.64cvss 9.8epss 0.02
deep.assign npm package 0.0.0-alpha.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution').
- risk 0.64cvss 9.8epss 0.02
All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.
- risk 0.64cvss 9.8epss 0.02
All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.