6.3

CVE-2024-39001

Exploit
ag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ag-gridAg-grid Version < 31.3.4
Ag-gridAg-grid Version >= 32.0.0 < 32.0.2
Ag-gridAg Charts Version < 9.3.2
Ag-gridAg Charts Version >= 10.0.0 < 10.0.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.83% 0.527
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.3 2.8 3.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

https://gist.github.com/mestrtee/18e8c27f3a6376e7cf082cfe1ca766fa
Third Party Advisory
Exploit
https://gist.github.com/mestrtee/c1590660750744f25e86ba1bf240844b
Third Party Advisory
Exploit
https://gist.github.com/mestrtee/f8037d492dab0d77bca719e05d31c08b
Third Party Advisory
Exploit