CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Parent: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

540 vulnerabilities with CWE-1321
CVE-2023-30857 LOW
aedart/ion < 0.6.1 - Prototype Pollution in MetadataRecord Merge
CVSS 3.7
CVE-2023-30363 CRITICAL
vConsole < 3.15.1 - Prototype Pollution via setOptions in core.ts
CVSS 9.8
CVE-2023-30533 HIGH
SheetJS Community Edition < 0.19.3 - Prototype Pollution via Crafted File
CVSS 7.8
CVE-2023-26122 HIGH
safe-eval < 0.4.1 - Sandbox Bypass via Prototype Pollution
CVSS 8.8
CVE-2023-26121 HIGH
safe-eval < 0.4.1 - Prototype Pollution via safeEval Function
CVSS 7.5
CVE-2023-0842 MEDIUM
xml2js 0.4.23 - Prototype Pollution via __proto__ Property
CVSS 5.3
CVE-2023-28427 HIGH
matrix-js-sdk <24.0.0 - Info Disclosure
CVSS 8.2
CVE-2023-28103 HIGH
matrix-react-sdk < 3.69.0 - Prototype Pollution via Remote Server Data
CVSS 8.2
CVE-2023-26113 HIGH
collection.js <6.8.1 - Info Disclosure
CVSS 7.5
CVE-2023-26106 HIGH
dot-lens < 1.2.3 - Prototype Pollution via set() Function
CVSS 7.5
CVE-2023-26105 HIGH
Package Utilities - Prototype Pollution
CVSS 7.5
CVE-2023-26102 HIGH
rangy - Prototype Pollution via extend() Function
CVSS 7.5
CVE-2023-23917 HIGH
Rocket.Chat < 5.2.0 - Prototype Pollution leading to Remote Code Execution
CVSS 8.8
CVE-2022-36060 HIGH
matrix-react-sdk < 3.53.0 - Denial of Service via Prototype Pollution
CVSS 8.2
CVE-2022-36059 HIGH
matrix-js-sdk <19.4.0 - Info Disclosure
CVSS 8.2
CVE-2022-3901 HIGH
Visioweb.js 1.10.6 - Prototype Pollution leading to Cross-Site Scripting
CVSS 7.2
CVE-2022-4742 MEDIUM
json-pointer < 0.6.2 - Prototype Pollution via set Function
CVSS 6.3
CVE-2022-46175 HIGH
json5 <1.0.2 and >=2.0.0 <2.2.2 - Prototype Pollution via __proto__ Key Parsing
CVSS 7.1
CVE-2022-2200 HIGH
Firefox < 102.0 and Firefox ESR < 91.11 - Prototype Pollution leading to Privileged Code Execution
CVSS 8.8
CVE-2022-1802 HIGH
Firefox < 100.0.2, Firefox ESR < 91.9.1, Thunderbird < 91.9.1 - Privileged JavaScript Execution via Prototype Pollution
CVSS 8.8
CVE-2022-1529 HIGH
Firefox < 100.0.2 and Firefox ESR < 91.9.1 - Prototype Pollution via Parent Process Message Handling
CVSS 8.8
CVE-2022-25904 HIGH
safe-eval < 0.4.1 - Prototype Pollution via safeEval Function
CVSS 7.5
CVE-2022-24999 HIGH
QS < 6.2.4 - Prototype Pollution
CVSS 7.5
CVE-2022-41878 HIGH
Parse Server <5.3.2, <4.10.19 - Auth Bypass
CVSS 7.2
CVE-2022-41879 HIGH
Parse Server <5.3.3,4.10.20 - Prototype Pollution
CVSS 7.2
Details
Vulnerabilities 540