CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Description
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-180 · CAPEC-77
CVEs mapped to this weakness (612)
page 9 of 31| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-28278 | Cri | 0.57 | 9.8 | 0.03 | Dec 29, 2020 | Prototype pollution vulnerability in 'shvl' versions 1.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead to remote code execution. | ||
| CVE-2020-28277 | Cri | 0.57 | 9.8 | 0.03 | Dec 29, 2020 | Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service and may lead to remote code execution. | ||
| CVE-2020-28273 | Cri | 0.57 | 9.8 | 0.04 | Dec 2, 2020 | Prototype pollution vulnerability in 'set-in' versions 1.0.0 through 2.0.0 allows attacker to cause a denial of service and may lead to remote code execution. | ||
| CVE-2020-28272 | Cri | 0.57 | 9.8 | 0.03 | Dec 2, 2020 | Prototype pollution vulnerability in 'keyget' versions 1.0.0 through 2.2.0 allows attacker to cause a denial of service and may lead to remote code execution. | ||
| CVE-2020-28271 | Cri | 0.57 | 9.8 | 0.03 | Nov 12, 2020 | Prototype pollution vulnerability in 'deephas' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution. | ||
| CVE-2020-28270 | Cri | 0.57 | 9.8 | 0.04 | Nov 12, 2020 | Prototype pollution vulnerability in 'object-hierarchy-access' versions 0.2.0 through 0.32.0 allows attacker to cause a denial of service and may lead to remote code execution. | ||
| CVE-2020-7724 | Cri | 0.57 | 9.8 | 0.02 | Sep 1, 2020 | All versions of package tiny-conf are vulnerable to Prototype Pollution via the set function. | ||
| CVE-2020-7722 | Cri | 0.57 | 9.8 | 0.02 | Sep 1, 2020 | All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function. | ||
| CVE-2020-7720 | Cri | 0.57 | 9.8 | 0.03 | Sep 1, 2020 | The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions. | ||
| CVE-2020-7719 | Cri | 0.57 | 9.8 | 0.03 | Sep 1, 2020 | Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function. | ||
| CVE-2020-7715 | Cri | 0.57 | 9.8 | 0.02 | Sep 1, 2020 | All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function. | ||
| CVE-2020-7713 | Cri | 0.57 | 9.8 | 0.02 | Sep 1, 2020 | All versions of package arr-flatten-unflatten are vulnerable to Prototype Pollution via the constructor. | ||
| CVE-2020-7708 | Cri | 0.57 | 9.8 | 0.03 | Aug 18, 2020 | The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via the set, unSet, pushVal and pullVal functions. | ||
| CVE-2020-7707 | Cri | 0.57 | 9.8 | 0.03 | Aug 18, 2020 | The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function. | ||
| CVE-2020-7706 | Cri | 0.57 | 9.8 | 0.03 | Aug 18, 2020 | The package connie-lang before 0.1.1 are vulnerable to Prototype Pollution in the configuration language library used by connie. | ||
| CVE-2020-7704 | Cri | 0.57 | 9.8 | 0.03 | Aug 17, 2020 | The package linux-cmdline before 1.0.1 are vulnerable to Prototype Pollution via the constructor. | ||
| CVE-2020-7701 | Cri | 0.57 | 9.8 | 0.02 | Aug 14, 2020 | madlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue. | ||
| CVE-2020-11066 | Hig | 0.57 | 8.7 | 0.01 | May 14, 2020 | In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, calling unserialize() on malicious user-submitted content can lead to modification of dynamically-determined object attributes and result in triggering… | ||
| CVE-2019-19919 | Cri | 0.57 | 9.8 | 0.07 | Dec 20, 2019 | Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads. | ||
| CVE-2019-17316 | Hig | 0.57 | 8.8 | 0.01 | Oct 7, 2019 | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Import module by a Regular user. |
- risk 0.57cvss 9.8epss 0.03
Prototype pollution vulnerability in 'shvl' versions 1.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
- risk 0.57cvss 9.8epss 0.03
Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
- risk 0.57cvss 9.8epss 0.04
Prototype pollution vulnerability in 'set-in' versions 1.0.0 through 2.0.0 allows attacker to cause a denial of service and may lead to remote code execution.
- risk 0.57cvss 9.8epss 0.03
Prototype pollution vulnerability in 'keyget' versions 1.0.0 through 2.2.0 allows attacker to cause a denial of service and may lead to remote code execution.
- risk 0.57cvss 9.8epss 0.03
Prototype pollution vulnerability in 'deephas' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.
- risk 0.57cvss 9.8epss 0.04
Prototype pollution vulnerability in 'object-hierarchy-access' versions 0.2.0 through 0.32.0 allows attacker to cause a denial of service and may lead to remote code execution.
- risk 0.57cvss 9.8epss 0.02
All versions of package tiny-conf are vulnerable to Prototype Pollution via the set function.
- risk 0.57cvss 9.8epss 0.02
All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function.
- risk 0.57cvss 9.8epss 0.03
The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.
- risk 0.57cvss 9.8epss 0.03
Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function.
- risk 0.57cvss 9.8epss 0.02
All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function.
- risk 0.57cvss 9.8epss 0.02
All versions of package arr-flatten-unflatten are vulnerable to Prototype Pollution via the constructor.
- risk 0.57cvss 9.8epss 0.03
The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via the set, unSet, pushVal and pullVal functions.
- risk 0.57cvss 9.8epss 0.03
The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.
- risk 0.57cvss 9.8epss 0.03
The package connie-lang before 0.1.1 are vulnerable to Prototype Pollution in the configuration language library used by connie.
- risk 0.57cvss 9.8epss 0.03
The package linux-cmdline before 1.0.1 are vulnerable to Prototype Pollution via the constructor.
- risk 0.57cvss 9.8epss 0.02
madlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue.
- risk 0.57cvss 8.7epss 0.01
In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, calling unserialize() on malicious user-submitted content can lead to modification of dynamically-determined object attributes and result in triggering…
- risk 0.57cvss 9.8epss 0.07
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.
- risk 0.57cvss 8.8epss 0.01
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Import module by a Regular user.