CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Description
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-180 · CAPEC-77
CVEs mapped to this weakness (612)
page 7 of 31| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-2972 | Cri | 0.57 | 9.8 | 0.01 | May 30, 2023 | Prototype Pollution in GitHub repository antfu/utils prior to 0.7.3. | ||
| CVE-2023-30363 | Cri | 0.57 | 9.8 | 0.01 | Apr 26, 2023 | vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts. | ||
| CVE-2023-26122 | Hig | 0.57 | 8.8 | 0.02 | Apr 11, 2023 | All versions of the package safe-eval are vulnerable to Sandbox Bypass due to improper input sanitization. The vulnerability is derived from prototype pollution exploitation. Exploiting this vulnerability might result in remote code execution ("RCE"). **Vulnerable… | ||
| CVE-2023-23917 | Hig | 0.57 | 8.8 | 0.01 | Feb 23, 2023 | A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the admin account. Any user can create their own server in your cloud and become an admin so this vulnerability could affect the cloud infrastructure. This attack… | ||
| CVE-2022-37623 | Cri | 0.57 | 9.8 | 0.01 | Oct 31, 2022 | Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the shimPath variable in resolve-shims.js. | ||
| CVE-2022-37621 | Cri | 0.57 | 9.8 | 0.01 | Oct 28, 2022 | Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the fullPath variable in resolve-shims.js. | ||
| CVE-2022-37601 | Cri | 0.57 | 9.8 | 0.03 | Oct 12, 2022 | Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3. | ||
| CVE-2022-37611 | Cri | 0.57 | 9.8 | 0.01 | Oct 12, 2022 | Prototype pollution vulnerability in tschaub gh-pages 3.1.0 via the partial variable in util.js. | ||
| CVE-2022-37617 | Cri | 0.57 | 9.8 | 0.01 | Oct 11, 2022 | Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the k variable in resolve-shims.js. | ||
| CVE-2022-37616 | Cri | 0.57 | 9.8 | 0.02 | Oct 11, 2022 | A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third… | ||
| CVE-2022-1295 | Cri | 0.57 | 9.8 | 0.01 | Apr 11, 2022 | Prototype Pollution in GitHub repository alvarotrigo/fullpage.js prior to 4.0.2. | ||
| CVE-2022-26260 | Cri | 0.57 | 9.8 | 0.01 | Mar 22, 2022 | Simple-Plist v1.3.0 was discovered to contain a prototype pollution vulnerability via .parse(). | ||
| CVE-2021-44906 | Cri | 0.57 | 9.8 | 0.05 | Mar 17, 2022 | Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95). | ||
| CVE-2021-44908 | Cri | 0.57 | 9.8 | 0.02 | Mar 17, 2022 | SailsJS Sails.js <=1.4.0 is vulnerable to Prototype Pollution via controller/load-action-modules.js, function loadActionModules(). | ||
| CVE-2022-22912 | Cri | 0.57 | 9.8 | 0.03 | Feb 17, 2022 | Prototype pollution vulnerability via .parse() in Plist before v3.0.4 allows attackers to cause a Denial of Service (DoS) and may lead to remote code execution. | ||
| CVE-2021-23555 | Cri | 0.57 | 9.8 | 0.03 | Feb 11, 2022 | The package vm2 before 3.9.6 are vulnerable to Sandbox Bypass via direct access to host error objects generated by node internals during generation of a stacktraces, which can lead to execution of arbitrary code on the host machine. | ||
| CVE-2021-3815 | Cri | 0.57 | 9.8 | 0.01 | Dec 8, 2021 | utils.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | ||
| CVE-2021-3918 | Cri | 0.57 | 9.8 | 0.04 | Nov 13, 2021 | json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | ||
| CVE-2021-23449 | Cri | 0.57 | 9.8 | 0.04 | Oct 18, 2021 | This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitrary code on the host machine. | ||
| CVE-2021-3666 | Cri | 0.57 | 9.8 | 0.01 | Sep 13, 2021 | body-parser-xml is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
- risk 0.57cvss 9.8epss 0.01
Prototype Pollution in GitHub repository antfu/utils prior to 0.7.3.
- risk 0.57cvss 9.8epss 0.01
vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts.
- risk 0.57cvss 8.8epss 0.02
All versions of the package safe-eval are vulnerable to Sandbox Bypass due to improper input sanitization. The vulnerability is derived from prototype pollution exploitation. Exploiting this vulnerability might result in remote code execution ("RCE"). **Vulnerable…
- risk 0.57cvss 8.8epss 0.01
A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the admin account. Any user can create their own server in your cloud and become an admin so this vulnerability could affect the cloud infrastructure. This attack…
- risk 0.57cvss 9.8epss 0.01
Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the shimPath variable in resolve-shims.js.
- risk 0.57cvss 9.8epss 0.01
Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the fullPath variable in resolve-shims.js.
- risk 0.57cvss 9.8epss 0.03
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
- risk 0.57cvss 9.8epss 0.01
Prototype pollution vulnerability in tschaub gh-pages 3.1.0 via the partial variable in util.js.
- risk 0.57cvss 9.8epss 0.01
Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the k variable in resolve-shims.js.
- risk 0.57cvss 9.8epss 0.02
A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third…
- risk 0.57cvss 9.8epss 0.01
Prototype Pollution in GitHub repository alvarotrigo/fullpage.js prior to 4.0.2.
- risk 0.57cvss 9.8epss 0.01
Simple-Plist v1.3.0 was discovered to contain a prototype pollution vulnerability via .parse().
- risk 0.57cvss 9.8epss 0.05
Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
- risk 0.57cvss 9.8epss 0.02
SailsJS Sails.js <=1.4.0 is vulnerable to Prototype Pollution via controller/load-action-modules.js, function loadActionModules().
- risk 0.57cvss 9.8epss 0.03
Prototype pollution vulnerability via .parse() in Plist before v3.0.4 allows attackers to cause a Denial of Service (DoS) and may lead to remote code execution.
- risk 0.57cvss 9.8epss 0.03
The package vm2 before 3.9.6 are vulnerable to Sandbox Bypass via direct access to host error objects generated by node internals during generation of a stacktraces, which can lead to execution of arbitrary code on the host machine.
- risk 0.57cvss 9.8epss 0.01
utils.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
- risk 0.57cvss 9.8epss 0.04
json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
- risk 0.57cvss 9.8epss 0.04
This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitrary code on the host machine.
- risk 0.57cvss 9.8epss 0.01
body-parser-xml is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')