Description
Prototype pollution vulnerability in ‘js-extend’ versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.0.1
References
- GHSA-mh82-55cm-6gfh
- www.whitesourcesoftware.com
- CVE-2021-25945
- CWE-1321
- CWE-915
- CAPEC-310
- OWASP 2021-A6
- OWASP 2021-A8
Related Issues
- Prototype Pollution Vulnerability in object-collider - CVE-2021-25914
- Starcounter-Jack JSON-Patch Prototype Pollution vulnerability - CVE-2021-4279
- Prototype Pollution in object-extend - CVE-2021-23702
- jquery-plugin-query-object contains prototype pollution vulnerability - CVE-2021-20083
You might also like:
- Tags:
- npm
- js-extend
Anything's wrong? Let us know Last updated on January 27, 2023


