CVE-2024-57708

MEDIUM

OneTrust SDK <6.33.0 - DoS

Title source: llm

Description

An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __proto__, and Object.assign components. NOTE: this is disputed by the Supplier who does not agree it is a prototype pollution vulnerability.

Exploits (1)

exploitdb WORKING POC
by Alameen Karim Merali · textremotelinux
https://www.exploit-db.com/exploits/52340

Scores

CVSS v3 5.7
EPSS 0.0057
EPSS Percentile 68.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-1321 CWE-400 CWE-471 CWE-915
Status published
Published Jun 25, 2025
Tracked Since Feb 18, 2026