VYPR

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

VariantIncomplete

Description

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-180 · CAPEC-77

CVEs mapped to this weakness (612)

page 9 of 31
  • CVE-2020-28278CriDec 29, 2020
    risk 0.57cvss 9.8epss 0.03

    Prototype pollution vulnerability in 'shvl' versions 1.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2020-28277CriDec 29, 2020
    risk 0.57cvss 9.8epss 0.03

    Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2020-28273CriDec 2, 2020
    risk 0.57cvss 9.8epss 0.04

    Prototype pollution vulnerability in 'set-in' versions 1.0.0 through 2.0.0 allows attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2020-28272CriDec 2, 2020
    risk 0.57cvss 9.8epss 0.03

    Prototype pollution vulnerability in 'keyget' versions 1.0.0 through 2.2.0 allows attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2020-28271CriNov 12, 2020
    risk 0.57cvss 9.8epss 0.03

    Prototype pollution vulnerability in 'deephas' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2020-28270CriNov 12, 2020
    risk 0.57cvss 9.8epss 0.04

    Prototype pollution vulnerability in 'object-hierarchy-access' versions 0.2.0 through 0.32.0 allows attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2020-7724CriSep 1, 2020
    risk 0.57cvss 9.8epss 0.02

    All versions of package tiny-conf are vulnerable to Prototype Pollution via the set function.

  • CVE-2020-7722CriSep 1, 2020
    risk 0.57cvss 9.8epss 0.02

    All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function.

  • CVE-2020-7720CriSep 1, 2020
    risk 0.57cvss 9.8epss 0.03

    The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.

  • CVE-2020-7719CriSep 1, 2020
    risk 0.57cvss 9.8epss 0.03

    Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function.

  • CVE-2020-7715CriSep 1, 2020
    risk 0.57cvss 9.8epss 0.02

    All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function.

  • CVE-2020-7713CriSep 1, 2020
    risk 0.57cvss 9.8epss 0.02

    All versions of package arr-flatten-unflatten are vulnerable to Prototype Pollution via the constructor.

  • CVE-2020-7708CriAug 18, 2020
    risk 0.57cvss 9.8epss 0.03

    The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via the set, unSet, pushVal and pullVal functions.

  • CVE-2020-7707CriAug 18, 2020
    risk 0.57cvss 9.8epss 0.03

    The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.

  • CVE-2020-7706CriAug 18, 2020
    risk 0.57cvss 9.8epss 0.03

    The package connie-lang before 0.1.1 are vulnerable to Prototype Pollution in the configuration language library used by connie.

  • CVE-2020-7704CriAug 17, 2020
    risk 0.57cvss 9.8epss 0.03

    The package linux-cmdline before 1.0.1 are vulnerable to Prototype Pollution via the constructor.

  • CVE-2020-7701CriAug 14, 2020
    risk 0.57cvss 9.8epss 0.02

    madlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue.

  • CVE-2020-11066HigMay 14, 2020
    risk 0.57cvss 8.7epss 0.01

    In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, calling unserialize() on malicious user-submitted content can lead to modification of dynamically-determined object attributes and result in triggering…

  • CVE-2019-19919CriDec 20, 2019
    risk 0.57cvss 9.8epss 0.07

    Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.

  • CVE-2019-17316HigOct 7, 2019
    risk 0.57cvss 8.8epss 0.01

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Import module by a Regular user.