CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Description
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-180 · CAPEC-77
CVEs mapped to this weakness (612)
page 3 of 31| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-25953 | Cri | 0.64 | 9.8 | 0.03 | Jul 14, 2021 | Prototype pollution vulnerability in 'putil-merge' versions1.0.0 through 3.6.6 allows attacker to cause a denial of service and may lead to remote code execution. | ||
| CVE-2021-25948 | Cri | 0.64 | 9.8 | 0.03 | Jun 10, 2021 | Prototype pollution vulnerability in 'expand-hash' versions 0.1.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution. | ||
| CVE-2021-25945 | Cri | 0.64 | 9.8 | 0.03 | May 26, 2021 | Prototype pollution vulnerability in 'js-extend' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution. | ||
| CVE-2021-25946 | Cri | 0.64 | 9.8 | 0.03 | May 25, 2021 | Prototype pollution vulnerability in `nconf-toml` versions 0.0.1 through 0.0.2 allows an attacker to cause a denial of service and may lead to remote code execution. | ||
| CVE-2021-25944 | Cri | 0.64 | 9.8 | 0.03 | May 25, 2021 | Prototype pollution vulnerability in 'deep-defaults' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution. | ||
| CVE-2021-25943 | — | Cri | 0.64 | 9.8 | 0.03 | May 14, 2021 | Prototype pollution vulnerability in '101' versions 1.0.0 through 1.6.3 allows an attacker to cause a denial of service and may lead to remote code execution. | |
| CVE-2021-25928 | Cri | 0.64 | 9.8 | 0.03 | Apr 26, 2021 | Prototype pollution vulnerability in 'safe-obj' versions 1.0.0 through 1.0.2 allows an attacker to cause a denial of service and may lead to remote code execution. | ||
| CVE-2020-28282 | Cri | 0.64 | 9.8 | 0.04 | Dec 29, 2020 | Prototype pollution vulnerability in 'getobject' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution. | ||
| CVE-2020-28281 | Cri | 0.64 | 9.8 | 0.04 | Dec 29, 2020 | Prototype pollution vulnerability in 'set-object-value' versions 0.0.0 through 0.0.5 allows an attacker to cause a denial of service and may lead to remote code execution. | ||
| CVE-2020-28276 | Cri | 0.64 | 9.8 | 0.03 | Dec 29, 2020 | Prototype pollution vulnerability in 'deep-set' versions 1.0.0 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution. | ||
| CVE-2020-28269 | Cri | 0.64 | 9.8 | 0.04 | Nov 12, 2020 | Prototype pollution vulnerability in 'field' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution. | ||
| CVE-2020-8158 | Cri | 0.64 | 9.8 | 0.02 | Sep 18, 2020 | Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks. | ||
| CVE-2020-7727 | Cri | 0.64 | 9.8 | 0.02 | Sep 1, 2020 | All versions of package gedi are vulnerable to Prototype Pollution via the set function. | ||
| CVE-2020-7726 | Cri | 0.64 | 9.8 | 0.02 | Sep 1, 2020 | All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function. | ||
| CVE-2020-7725 | Cri | 0.64 | 9.8 | 0.02 | Sep 1, 2020 | All versions of package worksmith are vulnerable to Prototype Pollution via the setValue function. | ||
| CVE-2020-7723 | Cri | 0.64 | 9.8 | 0.02 | Sep 1, 2020 | All versions of package promisehelpers are vulnerable to Prototype Pollution via the insert function. | ||
| CVE-2020-7721 | Cri | 0.64 | 9.8 | 0.02 | Sep 1, 2020 | All versions of package node-oojs are vulnerable to Prototype Pollution via the setPath function. | ||
| CVE-2020-7718 | Cri | 0.64 | 9.8 | 0.02 | Sep 1, 2020 | All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions. | ||
| CVE-2020-7717 | Cri | 0.64 | 9.8 | 0.02 | Sep 1, 2020 | All versions of package dot-notes are vulnerable to Prototype Pollution via the create function. | ||
| CVE-2020-7716 | Cri | 0.64 | 9.8 | 0.02 | Sep 1, 2020 | All versions of package deeps are vulnerable to Prototype Pollution via the set function. |
- risk 0.64cvss 9.8epss 0.03
Prototype pollution vulnerability in 'putil-merge' versions1.0.0 through 3.6.6 allows attacker to cause a denial of service and may lead to remote code execution.
- risk 0.64cvss 9.8epss 0.03
Prototype pollution vulnerability in 'expand-hash' versions 0.1.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
- risk 0.64cvss 9.8epss 0.03
Prototype pollution vulnerability in 'js-extend' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
- risk 0.64cvss 9.8epss 0.03
Prototype pollution vulnerability in `nconf-toml` versions 0.0.1 through 0.0.2 allows an attacker to cause a denial of service and may lead to remote code execution.
- risk 0.64cvss 9.8epss 0.03
Prototype pollution vulnerability in 'deep-defaults' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.
- risk 0.64cvss 9.8epss 0.03
Prototype pollution vulnerability in '101' versions 1.0.0 through 1.6.3 allows an attacker to cause a denial of service and may lead to remote code execution.
- risk 0.64cvss 9.8epss 0.03
Prototype pollution vulnerability in 'safe-obj' versions 1.0.0 through 1.0.2 allows an attacker to cause a denial of service and may lead to remote code execution.
- risk 0.64cvss 9.8epss 0.04
Prototype pollution vulnerability in 'getobject' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution.
- risk 0.64cvss 9.8epss 0.04
Prototype pollution vulnerability in 'set-object-value' versions 0.0.0 through 0.0.5 allows an attacker to cause a denial of service and may lead to remote code execution.
- risk 0.64cvss 9.8epss 0.03
Prototype pollution vulnerability in 'deep-set' versions 1.0.0 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
- risk 0.64cvss 9.8epss 0.04
Prototype pollution vulnerability in 'field' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
- risk 0.64cvss 9.8epss 0.02
Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks.
- risk 0.64cvss 9.8epss 0.02
All versions of package gedi are vulnerable to Prototype Pollution via the set function.
- risk 0.64cvss 9.8epss 0.02
All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function.
- risk 0.64cvss 9.8epss 0.02
All versions of package worksmith are vulnerable to Prototype Pollution via the setValue function.
- risk 0.64cvss 9.8epss 0.02
All versions of package promisehelpers are vulnerable to Prototype Pollution via the insert function.
- risk 0.64cvss 9.8epss 0.02
All versions of package node-oojs are vulnerable to Prototype Pollution via the setPath function.
- risk 0.64cvss 9.8epss 0.02
All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions.
- risk 0.64cvss 9.8epss 0.02
All versions of package dot-notes are vulnerable to Prototype Pollution via the create function.
- risk 0.64cvss 9.8epss 0.02
All versions of package deeps are vulnerable to Prototype Pollution via the set function.