This affects the package litespeed.js before 0.3.12; the package appwrite/server-ce from 0.12.0 and before 0.12.2, before 0.11.1. When parsing the query string in the getJsonFromUrl function, the key that is set in the result object is not properly sanitized leading to a Prototype Pollution vulnerability.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: snyk

Published: 2022-02-16T00:00:00

Updated: 2022-02-16T17:05:26

Reserved: 2021-01-08T00:00:00


Link: CVE-2021-23682

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-02-16T17:15:10.713

Modified: 2022-02-24T03:35:56.657


Link: CVE-2021-23682

JSON object: View

cve-icon Redhat Information

No data.

CWE