CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Parent: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

540 vulnerabilities with CWE-1321
CVE-2022-23624 HIGH
frourio-express < 0.26.0 - Improper Input Validation via Class-Validator Integration
CVSS 8.1
CVE-2022-23623 HIGH
frourio < 0.26.0 - Improper Input Validation in class-validator Integration
CVSS 8.1
CVE-2022-0432 MEDIUM
Mastodon < 3.5.0 - Prototype Pollution
CVSS 6.1
CVE-2021-26505 CRITICAL
hello.js 1.18.6 - Prototype Pollution via hello.utils.extend
CVSS 9.8
CVE-2021-4307 MEDIUM
Yomguithereal Baobab <2.6.0 - Prototype Pollution
CVSS 6.3
CVE-2021-4279 MEDIUM
Starcounter-Jack JSON-Patch <3.1.0 - Prototype Pollution
CVSS 6.3
CVE-2021-4278 MEDIUM
cronvel tree-kit <0.7.0 - Prototype Pollution
CVSS 5.5
CVE-2021-4264 MEDIUM
LinkedIn dustjs <3.0.0 - Prototype Pollution
CVSS 6.3
CVE-2021-4245 MEDIUM
chbrown rfc6902 - Prototype Pollution
CVSS 5.5
CVE-2021-23397 MEDIUM
@ianwalter/merge - Prototype Pollution via Merge Function
CVSS 5.6
CVE-2021-23373 HIGH
set-deep-prop - Prototype Pollution via Main Functionality
CVSS 7.5
CVE-2021-40663 CRITICAL
deep.assign 0.0.0-alpha.0 - Prototype Pollution
CVSS 9.8
CVE-2021-42581 CRITICAL
ramda < 0.27.0 - Prototype Pollution via mapObjIndexed Function
CVSS 9.1
CVE-2021-43138 HIGH
Async <2.6.4, <3.2.2 - Privilege Escalation
CVSS 7.8
CVE-2021-44906 CRITICAL
Minimist <=1.2.5 - Prototype Pollution via setKey Function
CVSS 9.8
CVE-2021-44908 CRITICAL
Sails.js <=1.4.0 - Prototype Pollution via loadActionModules()
CVSS 9.8
CVE-2021-23771 MEDIUM
notevil and argencoders-notevil - Prototype Pollution via Sandbox Escape
CVSS 6.5
CVE-2021-43956 MEDIUM
Atlassian Crucible and Fisheye < 4.8.9 - Prototype Pollution via jQuery Deserialize
CVSS 6.1
CVE-2021-23702 HIGH
object-extend < 0.5.0 - Prototype Pollution
CVSS 7.6
CVE-2021-23682 HIGH
appwrite < 0.11.1 and 0.12.0-0.12.2 - Prototype Pollution via Query String Parsing
CVSS 7.3
CVE-2021-23597 HIGH
fastify-multipart < 5.3.1 - Denial of Service via Constructor Property Bypass
CVSS 7.5
CVE-2021-23507 HIGH
object-path-set < 1.0.2 - Prototype Pollution via setPath Method
CVSS 7.5
CVE-2021-23497 HIGH
@strikeentco/set < 1.0.2 - Prototype Pollution leading to Denial of Service and Remote Code Execution
CVSS 7.5
CVE-2021-23470 HIGH
putil-merge < 3.8.0 - Prototype Pollution via Malicious Constructor Property
CVSS 8.2
CVE-2021-23760 MEDIUM
keyget - Prototype Pollution via set, push, and at Methods
CVSS 5.6
Details
Vulnerabilities 540