The package min-dash before 3.8.1 are vulnerable to Prototype Pollution via the set method due to missing enforcement of key types.
References
Link | Resource |
---|---|
https://github.com/bpmn-io/min-dash/blob/c4d579c0eb2ed0739592111c3906b198921d3f52/lib/object.js%23L32 | Broken Link Third Party Advisory |
https://github.com/bpmn-io/min-dash/pull/21 | Patch Third Party Advisory |
https://github.com/bpmn-io/min-dash/pull/21/commits/5ab05cbc4fd8d5eafb7db540c491ed0906b9d320 | Patch Third Party Advisory |
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2342127 | Exploit Mitigation Patch Third Party Advisory |
https://snyk.io/vuln/SNYK-JS-MINDASH-2340605 | Exploit Mitigation Patch Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: snyk
Published: 2022-01-21T00:00:00
Updated: 2022-01-21T20:05:13
Reserved: 2021-01-08T00:00:00
Link: CVE-2021-23460
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-01-21T20:15:07.903
Modified: 2022-01-26T21:25:55.873
Link: CVE-2021-23460
JSON object: View
Redhat Information
No data.
CWE