CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Parent: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

540 vulnerabilities with CWE-1321
CVE-2021-23383 MEDIUM
handlebars < 4.7.7 - Prototype Pollution via Template Compilation
CVSS 5.6
CVE-2021-28860 CRITICAL
mixme < 0.5.1 - Prototype Pollution via __proto__ in mutate() and merge()
CVSS 9.1
CVE-2021-25928 CRITICAL
safe-obj 1.0.0-1.0.2 - Prototype Pollution
CVSS 9.8
CVE-2021-25927 CRITICAL
safe-flat 2.0.0-2.0.1 - Prototype Pollution leading to Denial of Service and Remote Code Execution
CVSS 9.8
CVE-2021-20089 HIGH
purl 2.3.2 - Prototype Pollution
CVSS 8.8
CVE-2021-20086 HIGH
jquery-bbq 1.2.1 - Prototype Pollution
CVSS 8.8
CVE-2021-20085 HIGH
backbone-query-parameters 0.4.0 - Prototype Pollution
CVSS 8.8
CVE-2021-20083 HIGH
jquery-plugin-query-object 2.2.3 - Prototype Pollution
CVSS 8.8
CVE-2021-20088 HIGH
mootools-more 1.6.0 - Prototype Pollution
CVSS 8.8
CVE-2021-20087 HIGH
jquery-deparam 0.5.1 - Prototype Pollution
CVSS 8.8
CVE-2021-20084 HIGH
jquery-sparkle 1.5.2-beta - Prototype Pollution
CVSS 8.8
CVE-2021-25916 CRITICAL
patchmerge 1.0.0-1.0.1 - Prototype Pollution
CVSS 9.8
CVE-2021-21368 MEDIUM
msgpack5 < 3.6.1 - Prototype Poisoning via __proto__ Key Decoding
CVSS 6.7
CVE-2021-25915 CRITICAL
changeset 0.0.1-0.2.5 - Prototype Pollution leading to Denial of Service and Remote Code Execution
CVSS 9.8
CVE-2021-25914 CRITICAL
object-collider 1.0.0-1.0.3 - Prototype Pollution leading to Denial of Service and Remote Code Execution
CVSS 9.8
CVE-2021-21297 HIGH
Node-Red <1.2.8 - Prototype Pollution
CVSS 7.7
CVE-2021-27582 CRITICAL
MITREid Connect <1.3.3 - Code Injection
CVSS 9.1
CVE-2021-25913 CRITICAL
set-or-get 1.0.0-1.2.10 - Prototype Pollution
CVSS 9.8
CVE-2021-21304 HIGH
Dynamoose <2.7.0 - Prototype Pollution
CVSS 7.2
CVE-2021-25912 CRITICAL
dotty 0.0.1-0.1.0 - Prototype Pollution
CVSS 9.8
CVE-2021-23329 HIGH
nested-object-assign <1.0.4 - Info Disclosure
CVSS 7.5
CVE-2020-36632 MEDIUM
hughsk flat <5.0.0 - Prototype Pollution
CVSS 6.3
CVE-2020-36618 MEDIUM
Furqan node-whois - Prototype Pollution
CVSS 6.3
CVE-2020-36604 HIGH
hoek <8.5.1, <9.0.3 - Prototype Poisoning
CVSS 8.1
CVE-2020-28471 HIGH
properties-reader < 2.2.0 - Prototype Pollution
CVSS 7.3
Details
Vulnerabilities 540