8.8

CVE-2021-4264

Exploit

LinkedIn dustjs prototype pollution

A vulnerability was found in LinkedIn dustjs up to 2.x and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.0.0 is able to address this issue. The name of the patch is ddb6523832465d38c9d80189e9de60519ac307c3. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216464.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinkedinDustjs Version < 3.0.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.07% 0.605
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
cna@vuldb.com 6.3 2.8 3.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

https://github.com/linkedin/dustjs/commit/ddb6523832465d38c9d80189e9de60519ac307c3
Patch
Third Party Advisory
https://github.com/linkedin/dustjs/issues/804
Third Party Advisory
Exploit
Issue Tracking
https://github.com/linkedin/dustjs/pull/805
Patch
Third Party Advisory
Exploit
Issue Tracking
https://github.com/linkedin/dustjs/releases/tag/v3.0.0
Third Party Advisory
Release Notes
https://vuldb.com/?ctiid.216464
VDB Entry
https://vuldb.com/?id.216464
Third Party Advisory
VDB Entry