CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Parent: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

501 vulnerabilities with CWE-1321
CVE-2021-44906 CRITICAL
Minimist <=1.2.5 - Prototype Pollution via setKey Function
CVSS 9.8
CVE-2021-44908 CRITICAL
Sails.js <=1.4.0 - Prototype Pollution via loadActionModules()
CVSS 9.8
CVE-2021-23771 MEDIUM
notevil and argencoders-notevil - Prototype Pollution via Sandbox Escape
CVSS 6.5
CVE-2021-43956 MEDIUM
Atlassian Crucible and Fisheye < 4.8.9 - Prototype Pollution via jQuery Deserialize
CVSS 6.1
CVE-2021-23702 HIGH
object-extend < 0.5.0 - Prototype Pollution
CVSS 7.6
CVE-2021-23682 HIGH
appwrite < 0.11.1 and 0.12.0-0.12.2 - Prototype Pollution via Query String Parsing
CVSS 7.3
CVE-2021-23597 HIGH
fastify-multipart < 5.3.1 - Denial of Service via Constructor Property Bypass
CVSS 7.5
CVE-2021-23507 HIGH
object-path-set < 1.0.2 - Prototype Pollution via setPath Method
CVSS 7.5
CVE-2021-23497 HIGH
@strikeentco/set < 1.0.2 - Prototype Pollution leading to Denial of Service and Remote Code Execution
CVSS 7.5
CVE-2021-23470 HIGH
putil-merge < 3.8.0 - Prototype Pollution via Malicious Constructor Property
CVSS 8.2
CVE-2021-23760 MEDIUM
keyget - Prototype Pollution via set, push, and at Methods
CVSS 5.6
CVE-2021-23558 HIGH
bmoor < 0.10.1 - Prototype Pollution via set Function
CVSS 7.3
CVE-2021-23518 HIGH
cached-path-relative < 1.1.0 - Prototype Pollution via Cache Variable
CVSS 7.3
CVE-2021-23460 HIGH
min-dash < 3.8.1 - Prototype Pollution via Set Method
CVSS 7.5
CVE-2021-23594 CRITICAL
realms-shim - Sandbox Bypass via Prototype Pollution
CVSS 9.8
CVE-2021-23568 HIGH
extend2 < 1.0.1 - Prototype Pollution via Unsafe Recursive Merge
CVSS 7.3
CVE-2021-23543 CRITICAL
realms-shim - Sandbox Bypass via Prototype Pollution
CVSS 9.8
CVE-2021-43852 HIGH
OroPlatform <4.2.7 - Code Injection
CVSS 8.8
CVE-2021-23574 HIGH
js-data < 3.0.11 - Prototype Pollution via deepFillIn and set Functions
CVSS 7.5
CVE-2021-23450 HIGH
dojo < 1.17.0 - Prototype Pollution via setObject Function
CVSS 7.5
CVE-2021-23700 MEDIUM
merge-deep2 - Prototype Pollution via mergeDeep() Function
CVSS 6.5
CVE-2021-23663 MEDIUM
sey - Prototype Pollution via deepmerge()
CVSS 6.5
CVE-2021-23561 MEDIUM
comb - Prototype Pollution via deepMerge() Function
CVSS 6.5
CVE-2021-3815 CRITICAL
utils.js < 0.17.2 - Prototype Pollution
CVSS 9.8
CVE-2021-43787 CRITICAL
NodeBB 1.15.5-1.18.4 - Authenticated DOM-Based Cross-Site Scripting via Prototype Pollution
CVSS 9.0
Details
Vulnerabilities 501