VYPR

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

VariantIncomplete

Description

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-180 · CAPEC-77

CVEs mapped to this weakness (642)

page 33 of 33
  • CVE-2022-21803HigApr 12, 2022
    risk 0.00cvss 7.3epss 0.02

    This affects the package nconf before 0.11.4. When using the memory engine, it is possible to store a nested JSON representation of the configuration. The .set() function, that is responsible for setting the configuration properties, is vulnerable to Prototype Pollution. By…

  • CVE-2022-0432MedFeb 2, 2022
    risk 0.00cvss 6.1epss 0.04

    Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0.