VYPR

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

VariantIncomplete

Description

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-180 · CAPEC-77

CVEs mapped to this weakness (612)

page 3 of 31
  • CVE-2021-25953CriJul 14, 2021
    risk 0.64cvss 9.8epss 0.03

    Prototype pollution vulnerability in 'putil-merge' versions1.0.0 through 3.6.6 allows attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2021-25948CriJun 10, 2021
    risk 0.64cvss 9.8epss 0.03

    Prototype pollution vulnerability in 'expand-hash' versions 0.1.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2021-25945CriMay 26, 2021
    risk 0.64cvss 9.8epss 0.03

    Prototype pollution vulnerability in 'js-extend' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2021-25946CriMay 25, 2021
    risk 0.64cvss 9.8epss 0.03

    Prototype pollution vulnerability in `nconf-toml` versions 0.0.1 through 0.0.2 allows an attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2021-25944CriMay 25, 2021
    risk 0.64cvss 9.8epss 0.03

    Prototype pollution vulnerability in 'deep-defaults' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2021-25943CriMay 14, 2021
    risk 0.64cvss 9.8epss 0.03

    Prototype pollution vulnerability in '101' versions 1.0.0 through 1.6.3 allows an attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2021-25928CriApr 26, 2021
    risk 0.64cvss 9.8epss 0.03

    Prototype pollution vulnerability in 'safe-obj' versions 1.0.0 through 1.0.2 allows an attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2020-28282CriDec 29, 2020
    risk 0.64cvss 9.8epss 0.04

    Prototype pollution vulnerability in 'getobject' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2020-28281CriDec 29, 2020
    risk 0.64cvss 9.8epss 0.04

    Prototype pollution vulnerability in 'set-object-value' versions 0.0.0 through 0.0.5 allows an attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2020-28276CriDec 29, 2020
    risk 0.64cvss 9.8epss 0.03

    Prototype pollution vulnerability in 'deep-set' versions 1.0.0 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2020-28269CriNov 12, 2020
    risk 0.64cvss 9.8epss 0.04

    Prototype pollution vulnerability in 'field' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2020-8158CriSep 18, 2020
    risk 0.64cvss 9.8epss 0.02

    Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks.

  • CVE-2020-7727CriSep 1, 2020
    risk 0.64cvss 9.8epss 0.02

    All versions of package gedi are vulnerable to Prototype Pollution via the set function.

  • CVE-2020-7726CriSep 1, 2020
    risk 0.64cvss 9.8epss 0.02

    All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function.

  • CVE-2020-7725CriSep 1, 2020
    risk 0.64cvss 9.8epss 0.02

    All versions of package worksmith are vulnerable to Prototype Pollution via the setValue function.

  • CVE-2020-7723CriSep 1, 2020
    risk 0.64cvss 9.8epss 0.02

    All versions of package promisehelpers are vulnerable to Prototype Pollution via the insert function.

  • CVE-2020-7721CriSep 1, 2020
    risk 0.64cvss 9.8epss 0.02

    All versions of package node-oojs are vulnerable to Prototype Pollution via the setPath function.

  • CVE-2020-7718CriSep 1, 2020
    risk 0.64cvss 9.8epss 0.02

    All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions.

  • CVE-2020-7717CriSep 1, 2020
    risk 0.64cvss 9.8epss 0.02

    All versions of package dot-notes are vulnerable to Prototype Pollution via the create function.

  • CVE-2020-7716CriSep 1, 2020
    risk 0.64cvss 9.8epss 0.02

    All versions of package deeps are vulnerable to Prototype Pollution via the set function.