VYPR

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

VariantIncomplete

Description

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-180 · CAPEC-77

CVEs mapped to this weakness (612)

page 2 of 31
  • CVE-2024-39010CriJul 30, 2024
    risk 0.64cvss 9.8epss 0.01

    chase-moskal snapstate v0.0.9 was discovered to contain a prototype pollution via the function attemptNestedProperty. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-38984CriJul 30, 2024
    risk 0.64cvss 9.8epss 0.01

    Prototype Pollution in lukebond json-override 0.2.0 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via the __proto__ property.

  • CVE-2024-36572CriJul 30, 2024
    risk 0.64cvss 9.8epss 0.01

    Prototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the functions setDefaults, mergeBranch, and Object.setObjectValue.

  • CVE-2024-39014CriJul 1, 2024
    risk 0.64cvss 9.8epss 0.01

    ahilfoley cahil/utils v2.3.2 was discovered to contain a prototype pollution via the function set. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-39013CriJul 1, 2024
    risk 0.64cvss 9.8epss 0.01

    2o3t-utility v0.1.2 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-38993CriJul 1, 2024
    risk 0.64cvss 9.8epss 0.01

    rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-36582CriJun 17, 2024
    risk 0.64cvss 9.8epss 0.01

    alexbinary object-deep-assign 1.0.11 is vulnerable to Prototype Pollution via the extend() method of Module.deepAssign (/src/index.js)

  • CVE-2024-36580CriJun 17, 2024
    risk 0.64cvss 9.8epss 0.01

    A Prototype Pollution issue in cdr0 sg 1.0.10 allows an attacker to execute arbitrary code.

  • CVE-2022-37598CriOct 20, 2022
    risk 0.64cvss 9.8epss 0.01

    Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.js. NOTE: the vendor considers this an invalid report.

  • CVE-2022-37602CriOct 14, 2022
    risk 0.64cvss 9.8epss 0.02

    Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js.

  • CVE-2022-37614CriOct 12, 2022
    risk 0.64cvss 9.8epss 0.01

    Prototype pollution vulnerability in function enable in mockery.js in mfncooper mockery commit 822f0566fd6d72af8c943ae5ca2aa92e516aa2cf via the key variable in mockery.js.

  • CVE-2022-37609CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    Prototype pollution vulnerability in beautify-web js-beautify 1.13.7 via the name variable in options.js.

  • CVE-2022-37265CriSep 20, 2022
    risk 0.64cvss 9.8epss 0.01

    Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js.

  • CVE-2022-37258CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName variable in npm-convert.js.

  • CVE-2022-37264CriSep 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Prototype pollution vulnerability in stealjs steal 2.2.4 via the optionName variable in main.js.

  • CVE-2022-37266CriSep 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Prototype pollution vulnerability in function extend in babel.js in stealjs steal 2.2.4 via the key variable in babel.js.

  • CVE-2022-37257CriSep 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js.

  • CVE-2021-40663CriJun 30, 2022
    risk 0.64cvss 9.8epss 0.02

    deep.assign npm package 0.0.0-alpha.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution').

  • CVE-2021-23594CriJan 10, 2022
    risk 0.64cvss 9.8epss 0.02

    All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.

  • CVE-2021-23543CriJan 10, 2022
    risk 0.64cvss 9.8epss 0.02

    All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.