VYPR

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

VariantIncomplete

Description

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-180 · CAPEC-77

CVEs mapped to this weakness (612)

page 7 of 31
  • CVE-2023-2972CriMay 30, 2023
    risk 0.57cvss 9.8epss 0.01

    Prototype Pollution in GitHub repository antfu/utils prior to 0.7.3.

  • CVE-2023-30363CriApr 26, 2023
    risk 0.57cvss 9.8epss 0.01

    vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts.

  • CVE-2023-26122HigApr 11, 2023
    risk 0.57cvss 8.8epss 0.02

    All versions of the package safe-eval are vulnerable to Sandbox Bypass due to improper input sanitization. The vulnerability is derived from prototype pollution exploitation. Exploiting this vulnerability might result in remote code execution ("RCE"). **Vulnerable…

  • CVE-2023-23917HigFeb 23, 2023
    risk 0.57cvss 8.8epss 0.01

    A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the admin account. Any user can create their own server in your cloud and become an admin so this vulnerability could affect the cloud infrastructure. This attack…

  • CVE-2022-37623CriOct 31, 2022
    risk 0.57cvss 9.8epss 0.01

    Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the shimPath variable in resolve-shims.js.

  • CVE-2022-37621CriOct 28, 2022
    risk 0.57cvss 9.8epss 0.01

    Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the fullPath variable in resolve-shims.js.

  • CVE-2022-37601CriOct 12, 2022
    risk 0.57cvss 9.8epss 0.03

    Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.

  • CVE-2022-37611CriOct 12, 2022
    risk 0.57cvss 9.8epss 0.01

    Prototype pollution vulnerability in tschaub gh-pages 3.1.0 via the partial variable in util.js.

  • CVE-2022-37617CriOct 11, 2022
    risk 0.57cvss 9.8epss 0.01

    Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the k variable in resolve-shims.js.

  • CVE-2022-37616CriOct 11, 2022
    risk 0.57cvss 9.8epss 0.02

    A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third…

  • CVE-2022-1295CriApr 11, 2022
    risk 0.57cvss 9.8epss 0.01

    Prototype Pollution in GitHub repository alvarotrigo/fullpage.js prior to 4.0.2.

  • CVE-2022-26260CriMar 22, 2022
    risk 0.57cvss 9.8epss 0.01

    Simple-Plist v1.3.0 was discovered to contain a prototype pollution vulnerability via .parse().

  • CVE-2021-44906CriMar 17, 2022
    risk 0.57cvss 9.8epss 0.05

    Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).

  • CVE-2021-44908CriMar 17, 2022
    risk 0.57cvss 9.8epss 0.02

    SailsJS Sails.js <=1.4.0 is vulnerable to Prototype Pollution via controller/load-action-modules.js, function loadActionModules().

  • CVE-2022-22912CriFeb 17, 2022
    risk 0.57cvss 9.8epss 0.03

    Prototype pollution vulnerability via .parse() in Plist before v3.0.4 allows attackers to cause a Denial of Service (DoS) and may lead to remote code execution.

  • CVE-2021-23555CriFeb 11, 2022
    risk 0.57cvss 9.8epss 0.03

    The package vm2 before 3.9.6 are vulnerable to Sandbox Bypass via direct access to host error objects generated by node internals during generation of a stacktraces, which can lead to execution of arbitrary code on the host machine.

  • CVE-2021-3815CriDec 8, 2021
    risk 0.57cvss 9.8epss 0.01

    utils.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

  • CVE-2021-3918CriNov 13, 2021
    risk 0.57cvss 9.8epss 0.04

    json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

  • CVE-2021-23449CriOct 18, 2021
    risk 0.57cvss 9.8epss 0.04

    This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitrary code on the host machine.

  • CVE-2021-3666CriSep 13, 2021
    risk 0.57cvss 9.8epss 0.01

    body-parser-xml is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')