VYPR

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

VariantIncomplete

Description

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-180 · CAPEC-77

CVEs mapped to this weakness (612)

page 8 of 31
  • CVE-2021-3645CriSep 10, 2021
    risk 0.57cvss 9.8epss 0.01

    merge is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

  • CVE-2021-3766CriSep 6, 2021
    risk 0.57cvss 9.8epss 0.01

    objection.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

  • CVE-2021-3757CriSep 2, 2021
    risk 0.57cvss 9.8epss 0.02

    immer is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

  • CVE-2021-25952CriJul 7, 2021
    risk 0.57cvss 9.8epss 0.03

    Prototype pollution vulnerability in ‘just-safe-set’ versions 1.0.0 through 2.2.1 allows an attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2021-25949CriJun 10, 2021
    risk 0.57cvss 9.8epss 0.03

    Prototype pollution vulnerability in 'set-getter' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2021-25947CriJun 3, 2021
    risk 0.57cvss 9.8epss 0.03

    Prototype pollution vulnerability in 'nestie' versions 0.0.0 through 1.0.0 allows an attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2021-26707CriJun 2, 2021
    risk 0.57cvss 9.8epss 0.02

    The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications…

  • CVE-2021-25941CriMay 14, 2021
    risk 0.57cvss 9.8epss 0.03

    Prototype pollution vulnerability in 'deep-override' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2021-25927CriApr 26, 2021
    risk 0.57cvss 9.8epss 0.03

    Prototype pollution vulnerability in 'safe-flat' versions 2.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2021-20089HigApr 23, 2021
    risk 0.57cvss 8.8epss 0.02

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in purl 2.3.2 allows a malicious user to inject properties into Object.prototype.

  • CVE-2021-20085HigApr 23, 2021
    risk 0.57cvss 8.8epss 0.02

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in backbone-query-parameters 0.4.0 allows a malicious user to inject properties into Object.prototype.

  • CVE-2021-20088HigApr 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in mootools-more 1.6.0 allows a malicious user to inject properties into Object.prototype.

  • CVE-2021-20087HigApr 23, 2021
    risk 0.57cvss 8.8epss 0.02

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-deparam 0.5.1 allows a malicious user to inject properties into Object.prototype.

  • CVE-2021-20084HigApr 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-sparkle 1.5.2-beta allows a malicious user to inject properties into Object.prototype.

  • CVE-2021-25916CriMar 16, 2021
    risk 0.57cvss 9.8epss 0.04

    Prototype pollution vulnerability in 'patchmerge' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2021-25915CriMar 9, 2021
    risk 0.57cvss 9.8epss 0.04

    Prototype pollution vulnerability in 'changeset' versions 0.0.1 through 0.2.5 allows an attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2021-25914CriMar 1, 2021
    risk 0.57cvss 9.8epss 0.04

    Prototype pollution vulnerability in 'object-collider' versions 1.0.0 through 1.0.3 allows attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2021-25913CriFeb 8, 2021
    risk 0.57cvss 9.8epss 0.04

    Prototype pollution vulnerability in 'set-or-get' version 1.0.0 through 1.2.10 allows an attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2021-25912CriFeb 2, 2021
    risk 0.57cvss 9.8epss 0.03

    Prototype pollution vulnerability in 'dotty' versions 0.0.1 through 0.1.0 allows attackers to cause a denial of service and may lead to remote code execution.

  • CVE-2020-28279CriDec 29, 2020
    risk 0.57cvss 9.8epss 0.03

    Prototype pollution vulnerability in 'flattenizer' versions 0.0.5 through 1.0.5 allows an attacker to cause a denial of service and may lead to remote code execution.