9.8

CVE-2024-38996

Exploit
ag-grid-community v31.3.2 and ag-grid-enterprise v31.3.2 were discovered to contain a prototype pollution via the _.mergeDeep function. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ag-gridAg-grid Version < 31.3.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.16% 0.629
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

https://gist.github.com/mestrtee/18e8c27f3a6376e7cf082cfe1ca766fa
Third Party Advisory
Exploit
https://gist.github.com/mestrtee/c1590660750744f25e86ba1bf240844b
Third Party Advisory
Exploit
https://gist.github.com/mestrtee/f8037d492dab0d77bca719e05d31c08b
Third Party Advisory
Exploit