CVE-2021-1321
published 2021-02-04CVE-2021-1321: Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an…
PriorityP351high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
2.19%
80.6th percentile
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adaltas | mixme | >= 0 < 0.5.1 | 0.5.1 |
| algolia | algoliasearch-helper | >= 0 < 3.6.2 | 3.6.2 |
| algolia | algoliasearch-helper | >= 2.0.0-rc1 < 3.11.2 | 3.11.2 |
| baobab_project | baobab | >= 0 < 2.6.1 | 2.6.1 |
| bluespire | aurelia-path | >= 0 < 1.1.7 | 1.1.7 |
| bmoor_project | bmoor | >= 0 < 0.10.1 | 0.10.1 |
| cached-path-relative_project | cached-path-relative | >= 0 < 1.1.0 | 1.1.0 |
| changeset_project | changeset | >= 0.0.1 < 0.2.5 | 0.2.5 |
| cisco | cisco_small_business_rv_series_router_firmware | — | — |
| cisco | rv016_multi-wan_vpn_router_firmware | <= 4.2.3.14 | — |
| cisco | rv042_dual_wan_vpn_router_firmware | <= 4.2.3.14 | — |
| cisco | rv042g_dual_gigabit_wan_vpn_router_firmware | <= 4.2.3.14 | — |
| cisco | rv082_dual_wan_vpn_router_firmware | <= 4.2.3.14 | — |
| cisco | rv320_dual_gigabit_wan_vpn_router_firmware | <= 1.5.1.11 | — |
| cisco | rv325_dual_gigabit_wan_vpn_router_firmware | <= 1.5.1.11 | — |
| cisco | small_business_rv_series_routers | — | — |
| cronvel | tree-kit | >= 0 < 0.7.0 | 0.7.0 |
| deep-defaults_project | deep-defaults | 1.0.0 – 1.0.5 | — |
| deep-override_project | deep-override | >= 1.0.0 < 1.0.2 | 1.0.2 |
| dotty_project | dotty | >= 0 < 0.1.2 | 0.1.2 |
| dynamoose | dynamoose | >= 2.0.0 < 2.7.0 | 2.7.0 |
| ecomfe | zrender | >= 0 < 4.3.3 | 4.3.3 |
| ecomfe | zrender | >= 5.0.0 < 5.2.1 | 5.2.1 |
| fireblink | object-collider | >= 1.0.0 < 1.0.4 | 1.0.4 |
| fiznool | fiznool_body-parser-xml | >= 0 < 2.0.3 | 2.0.3 |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
ghsa9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_cisco7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
algoliasearch-helper: algoliasearch-helper prototype pollution
vendor_redhat·2025-09-27·CVSS 5.9
CVE-2025-3193 [MEDIUM] CWE-1321 algoliasearch-helper: algoliasearch-helper prototype pollution
algoliasearch-helper: algoliasearch-helper prototype pollution
Versions of the package algoliasearch-helper from 2.0.0-rc1 and before 3.11.2 are vulnerable to Prototype Pollution in the _merge() function in merge.js, which allows constructor.prototype to be written even though doing so throws an error. In the "extreme edge-case" that the resulting error is caught, code injected into the user-supplied search parameter may be exeucted.
This is related to but distinct from the issue reported in [CVE-2021-23433](https://security.snyk.io/vuln/SNYK-JS-ALGOLIASEARCHHELPER-1570421).
**NOTE:** This vulnerability is not exploitable in the default configuration of InstantSearch since searchParameters are not modifiable by users.
A prototype pollution flaw has been discovered in the npm algoliasearc
Red Hat
async: Prototype Pollution in async
vendor_redhat·2022-04-07·CVSS 7.8
CVE-2021-43138 [HIGH] CWE-1321 async: Prototype Pollution in async
async: Prototype Pollution in async
In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution.
A vulnerability was found in the async package. This flaw allows a malicious user to obtain privileges via the mapValues() method.
Package: openshift-logging/kibana6-rhel8 (Logging Subsystem for Red Hat OpenShift) - Not affected
Package: migration-toolkit-virtualization/mtv-ui-rhel8 (Migration Toolkit for Virtualization) - Fix deferred
Package: odo (OpenShift Developer Tools and Services) - Will not fix
Package: openshift-pipelines/pipelines-hub-api-rhel8 (OpenShift Pipelines) - Will not fix
Package: openshift-pipelines/pipelines-hub-db-migration-rhel8 (OpenShift Pipel
Red Hat
set-getter: prototype pollution in ‘set-getter may lead to DoS
vendor_redhat·2021-06-10·CVSS 9.8
CVE-2021-25949 [CRITICAL] CWE-1321 set-getter: prototype pollution in ‘set-getter may lead to DoS
set-getter: prototype pollution in ‘set-getter may lead to DoS
Prototype pollution vulnerability in 'set-getter' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution.
A prototype pollution vulnerability was found in ‘set-getter’. This issue allows an attacker to cause a denial of service and may also lead to remote code execution.
Statement: In the logging subsystem for Red Hat OpenShift, the vulnerable set-getter nodejs package is bundled in the ose-logging-kibana6 container as a transitive dependency, hence the direct impact is reduced to Moderate.
Package: openshift-logging/kibana6-rhel8 (Logging Subsystem for Red Hat OpenShift) - Not affected
Cisco
Cisco Small Business RV Series Routers Management Interface Remote Command Execution and Denial of Service Vulnerabilities
vendor_cisco·2021-02-03·CVSS 7.2
CVE-2021-1319 [HIGH] CWE-121 Cisco Small Business RV Series Routers Management Interface Remote Command Execution and Denial of Service Vulnerabilities
Cisco Small Business RV Series Routers Management Interface Remote Command Execution and Denial of Service Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly.
These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (Do
Cisco
Cisco Small Business RV Series Routers Management Interface Remote Command Execution and Denial of Service Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2021-1321 Cisco Small Business RV Series Routers Management Interface Remote Command Execution and Denial of Service Vulnerabilities
CVE-2021-1321: Cisco Small Business RV Series Routers Management Interface Remote Command Execution and Denial of Service Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial
GHSA
algoliasearch-helper is vulnerable to Prototype Pollution in _merge()
ghsa·2025-09-27·CVSS 9.8
CVE-2025-3193 [MEDIUM] CWE-1321 algoliasearch-helper is vulnerable to Prototype Pollution in _merge()
algoliasearch-helper is vulnerable to Prototype Pollution in _merge()
Versions of the package algoliasearch-helper from 2.0.0-rc1 and before 3.11.2 are vulnerable to Prototype Pollution in the _merge() function in merge.js, which allows constructor.prototype to be written even though doing so throws an error. In the "extreme edge-case" that the resulting error is caught, code injected into the user-supplied search parameter may be exeucted.
This is related to but distinct from the issue reported in [CVE-2021-23433](https://security.snyk.io/vuln/SNYK-JS-ALGOLIASEARCHHELPER-1570421).
**NOTE:** This vulnerability is not exploitable in the default configuration of InstantSearch since searchParameters are not modifiable by users.
GHSA
MrSwitch hello.js vulnerable to prototype pollution
ghsa·2023-08-11
CVE-2021-26505 [CRITICAL] CWE-1321 MrSwitch hello.js vulnerable to prototype pollution
MrSwitch hello.js vulnerable to prototype pollution
A prototype pollution vulnerability in MrSwitch hello.js prior to version 1.18.8 allows remote attackers to execute arbitrary code via `hello.utils.extend` function.
GHSA
Baobab vulnerable to Prototype Pollution
ghsa·2023-01-07
CVE-2021-4307 [CRITICAL] CWE-1321 Baobab vulnerable to Prototype Pollution
Baobab vulnerable to Prototype Pollution
A vulnerability was found in Yomguithereal Baobab up to 2.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack can be launched remotely. Upgrading to version 2.6.1 is able to address this issue. The name of the patch is c56639532a923d9a1600fb863ec7551b188b5d19. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217627.
GHSA
tree-kit vulnerable to Prototype Pollution
ghsa·2022-12-25
CVE-2021-4278 [HIGH] CWE-1321 tree-kit vulnerable to Prototype Pollution
tree-kit vulnerable to Prototype Pollution
A vulnerability classified as problematic has been found in cronvel tree-kit up to 0.6.x. This affects an unknown part. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). Upgrading to version 0.7.0 is able to address this issue. The name of the patch is a63f559c50d70e8cb2eaae670dec25d1dbc4afcd. It is recommended to upgrade the affected component. The identifier VDB-216765 was assigned to this vulnerability.
GHSA
Starcounter-Jack JSON-Patch Prototype Pollution vulnerability
ghsa·2022-12-25
CVE-2021-4279 [HIGH] CWE-1321 Starcounter-Jack JSON-Patch Prototype Pollution vulnerability
Starcounter-Jack JSON-Patch Prototype Pollution vulnerability
A vulnerability has been found in Starcounter-Jack JSON-Patch up to 3.1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.1.1 can address this issue. The name of the patch is 7ad6af41eabb2d799f698740a91284d762c955c9. It is recommended to upgrade the affected component. VDB-216778 is the identifier assigned to this vulnerability.
GHSA
npm package rfc6902 vulnerable to Prototype Pollution
ghsa·2022-12-15
CVE-2021-4245 [CRITICAL] CWE-1321 npm package rfc6902 vulnerable to Prototype Pollution
npm package rfc6902 vulnerable to Prototype Pollution
A vulnerability classified as problematic has been found in chbrown rfc6902. This affects an unknown part of the file pointer.ts. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The exploit has been disclosed to the public and may be used. The name of the patch is c006ce9faa43d31edb34924f1df7b79c137096cf. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-215883.
GHSA
set-deep-prop Prototype Pollution
ghsa·2022-07-26
CVE-2021-23373 [CRITICAL] CWE-1321 set-deep-prop Prototype Pollution
set-deep-prop Prototype Pollution
All versions of package set-deep-prop are vulnerable to Prototype Pollution via the main functionality.
GHSA
@ianwalter/merge Prototype Pollution via `merge` function
ghsa·2022-07-26
CVE-2021-23397 [MEDIUM] CWE-1321 @ianwalter/merge Prototype Pollution via `merge` function
@ianwalter/merge Prototype Pollution via `merge` function
All versions of package @ianwalter/merge are vulnerable to Prototype Pollution via the main (`merge`) function. @ianwalter/merge is [deprecated](https://github.com/ianwalter/merge/blob/master/README.md) and the maintainer suggests using [@generates/merger](https://github.com/generates/generates/tree/main/packages/merger) instead.
GHSA
GHSA-hcxg-m989-4j63: Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could all
ghsa_unreviewed·2022-05-24
CVE-2021-1321 [HIGH] CWE-121 GHSA-hcxg-m989-4j63: Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could all
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affect
GHSA
Changeset vulnerable to prototype pollution
ghsa·2022-05-24
CVE-2021-25915 [CRITICAL] CWE-1321 Changeset vulnerable to prototype pollution
Changeset vulnerable to prototype pollution
### Overview
Prototype pollution vulnerability in 'changeset' versions 0.0.1 through 0.2.5 allows attackers to cause a denial of service and may lead to remote code execution.
### Details
The npm module 'changeset' can be abused by Prototype Pollution vulnerability since the function 'apply()' does not check for the type of object before assigning value to the property. Due to this flaw an attacker could create a non-existent property or able to manipulate the property which leads to Denial of Service or potentially Remote code execution.
### PoC Details
The 'apply()' function accepts 'changes, target, modify' as argument. Due to the absence of validation on the values passed into the 'changes' argument, an attacker can supply a malicious valu
GHSA
deep-defaults vulnerable to prototype pollution
ghsa·2022-05-24
CVE-2021-25944 [CRITICAL] CWE-1321 deep-defaults vulnerable to prototype pollution
deep-defaults vulnerable to prototype pollution
### Overview
Prototype pollution vulnerability in 'deep-defaults' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.
### Details
The NPM module `deep-defaults` can be abused by Prototype Pollution vulnerability since the function `_deepDefaults()` does not check for the type of object before assigning value to the property. Due to this flaw an attacker could create a non-existent property or able to manipulate the property which leads to Denial of Service or potentially Remote code execution.
### PoC
The `_deepDefaults ()` function accepts `dest`, `src` as arguments. Due to the absence of validation on the values passed into the `src` argument, an attacker can supply a malicious
GHSA
Prototype Pollution in minimist
ghsa·2022-03-18
CVE-2021-44906 [CRITICAL] CWE-1321 Prototype Pollution in minimist
Prototype Pollution in minimist
Minimist prior to 1.2.6 and 0.2.4 is vulnerable to Prototype Pollution via file `index.js`, function `setKey()` (lines 69-95).
GHSA
Prototype Pollution in mixme
ghsa·2022-02-10
CVE-2021-28860 [CRITICAL] CWE-1321 Prototype Pollution in mixme
Prototype Pollution in mixme
Node.js mixme 0.5.0, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at risk causing a potential denial of service (DoS).
GHSA
Prototype Pollution in @strikeentco/set
ghsa·2022-02-05
CVE-2021-23497 [HIGH] CWE-1321 Prototype Pollution in @strikeentco/set
Prototype Pollution in @strikeentco/set
This affects the package @strikeentco/set before 1.0.2. It allows an attacker to cause a denial of service and may lead to remote code execution. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-STRIKEENTCOSET-1038821
GHSA
Prototype Pollution in putil-merge
ghsa·2022-02-05
CVE-2021-23470 [HIGH] CWE-1321 Prototype Pollution in putil-merge
Prototype Pollution in putil-merge
This affects the package putil-merge before 3.8.0. The merge() function does not check the values passed into the argument. An attacker can supply a malicious value by adjusting the value to include the constructor property. Note: This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-PUTILMERGE-1317077
GHSA
Prototype Pollution in bmoor
ghsa·2022-02-01·CVSS 9.8
CVE-2021-23558 [HIGH] CWE-1321 Prototype Pollution in bmoor
Prototype Pollution in bmoor
The package bmoor before 0.10.1 is vulnerable to Prototype Pollution due to missing sanitization in set function. **Note:** This vulnerability derives from an incomplete fix in [CVE-2020-7736](https://security.snyk.io/vuln/SNYK-JS-BMOOR-598664)
GHSA
Prototype Pollution in cached-path-relative
ghsa·2022-01-27
CVE-2021-23518 [HIGH] CWE-1321 Prototype Pollution in cached-path-relative
Prototype Pollution in cached-path-relative
The package cached-path-relative before 1.1.0 is vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using the origin path as __proto__, the attribute of the object is accessed instead of a path. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-72573
GHSA
Client-Side JavaScript Prototype Pollution in oro/platform
ghsa·2022-01-06
CVE-2021-43852 [MEDIUM] CWE-1321 Client-Side JavaScript Prototype Pollution in oro/platform
Client-Side JavaScript Prototype Pollution in oro/platform
### Summary
By sending a specially crafted request, an attacker could inject properties into existing JavaScript language construct prototypes, such as objects. Later this injection may lead to JS code execution by libraries that are vulnerable to Prototype Pollution.
### Workarounds
Configure WAF to drop requests containing next strings: `__proto__` , `constructor[prototype]`, `constructor.prototype`
GHSA
Prototype Pollution in js-data
ghsa·2022-01-06·CVSS 9.8
CVE-2021-23574 [HIGH] CWE-1321 Prototype Pollution in js-data
Prototype Pollution in js-data
All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn and the set functions. This is an incomplete fix of [CVE-2020-28442](https://snyk.io/vuln/SNYK-JS-JSDATA-1023655).
GHSA
Prototype Pollution in dojo
ghsa·2022-01-05
CVE-2021-23450 [HIGH] CWE-1321 Prototype Pollution in dojo
Prototype Pollution in dojo
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
GHSA
Prototype Pollution in algoliasearch-helper
ghsa·2021-11-23
CVE-2021-23433 [CRITICAL] CWE-1321 Prototype Pollution in algoliasearch-helper
Prototype Pollution in algoliasearch-helper
The package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in src/SearchParameters/index.jsSearchParameters._parseNumbers without any protection against prototype properties. Note that this vulnerability is only exploitable if the implementation allows users to define arbitrary search patterns.
GHSA
Prototype Pollution in dotty
ghsa·2021-11-08·CVSS 9.8
CVE-2021-23624 [CRITICAL] CWE-1321 Prototype Pollution in dotty
Prototype Pollution in dotty
This affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when the user-provided keys used in the path parameter are arrays.
GHSA
Prototype Pollution in node-jsonpointer
ghsa·2021-11-08
CVE-2021-23807 [MEDIUM] CWE-1321 Prototype Pollution in node-jsonpointer
Prototype Pollution in node-jsonpointer
This affects the package `jsonpointer` before `5.0.0`. A type confusion vulnerability can lead to a bypass of a previous Prototype Pollution fix when the pointer components are arrays.
GHSA
Prototype Pollution in json-pointer
ghsa·2021-11-08·CVSS 7.2
CVE-2021-23820 [MEDIUM] CWE-1321 Prototype Pollution in json-pointer
Prototype Pollution in json-pointer
This affects versions of package `json-pointer` up to and including `0.6.1`. A type confusion vulnerability can lead to a bypass of CVE-2020-7709 when the pointer components are arrays.
GHSA
Prototype pollution vulnerability in 'patchmerge'
ghsa·2021-10-13
CVE-2021-25916 [CRITICAL] CWE-1321 Prototype pollution vulnerability in 'patchmerge'
Prototype pollution vulnerability in 'patchmerge'
Prototype pollution vulnerability in 'patchmerge' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
GHSA
Prototype pollution in aurelia-path
ghsa·2021-09-27
CVE-2021-41097 [CRITICAL] CWE-1321 Prototype pollution in aurelia-path
Prototype pollution in aurelia-path
### Impact
The vulnerability exposes Aurelia application that uses `aurelia-path` package to parse a string. The majority of this will be Aurelia applications that employ the `aurelia-router` package. An example is this could allow an attacker to change the prototype of base object class `Object` by tricking an application to parse the following URL: `https://aurelia.io/blog/?__proto__[asdf]=asdf`
### Patches
The problem should be patched in version `1.1.7`. Any version earlier than this is vulnerable.
### Workarounds
A partial work around is to free the Object prototype:
```ts
Object.freeze(Object.prototype)
```
GHSA
Prototype Pollution in the merge and clone helper methods
ghsa·2021-09-20
CVE-2021-39227 [MEDIUM] CWE-1321 Prototype Pollution in the merge and clone helper methods
Prototype Pollution in the merge and clone helper methods
### Impact
Using `merge` and `clone` helper methods in the `src/core/util.ts` module will have prototype pollution. It will affect the popular data visualization library Apache ECharts, which is using and exported these two methods directly.
### Patches
It has been patched in https://github.com/ecomfe/zrender/pull/826.
Users should update zrender to `5.2.1`. and update echarts to `5.2.1` if project is using echarts.
### References
NA
### For more information
NA
GHSA
body-parser-xml vulnerable to Prototype Pollution
ghsa·2021-09-14
CVE-2021-3666 [HIGH] CWE-1321 body-parser-xml vulnerable to Prototype Pollution
body-parser-xml vulnerable to Prototype Pollution
body-parser-xml is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution').
GHSA
merge vulnerable to Prototype Pollution
ghsa·2021-09-13
CVE-2021-3645 [CRITICAL] CWE-1321 merge vulnerable to Prototype Pollution
merge vulnerable to Prototype Pollution
merge is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
GHSA
Prototype Pollution in immer
ghsa·2021-09-07
CVE-2021-3757 [HIGH] CWE-1321 Prototype Pollution in immer
Prototype Pollution in immer
immer is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution').
GHSA
objection.js Prototype Pollution vulnerability
ghsa·2021-09-07
CVE-2021-3766 [CRITICAL] CWE-1321 objection.js Prototype Pollution vulnerability
objection.js Prototype Pollution vulnerability
objection.js prior to version 2.2.16 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'). This issue is patched in version 2.2.16.
GHSA
Prototype Pollution in immer
ghsa·2021-09-02·CVSS 7.5
CVE-2021-23436 [HIGH] CWE-1321 Prototype Pollution in immer
Prototype Pollution in immer
This affects the package immer before 9.0.6. A type confusion vulnerability can lead to a bypass of CVE-2020-28477 when the user-provided keys used in the path parameter are arrays. In particular, this bypass is possible because the condition `(p === "__proto__" || p === "constructor")` in `applyPatches_` returns false if `p` is `['__proto__']` (or `['constructor']`). The `===` operator (strict equality operator) returns false if the operands have different type.
GHSA
Prototype Pollution in Proto
ghsa·2021-09-02
CVE-2021-23426 [HIGH] CWE-1321 Prototype Pollution in Proto
Prototype Pollution in Proto
This affects all versions of package Proto. It is possible to inject pollute the object property of an application using Proto by leveraging the merge function.
GHSA
Prototype Pollution in deepmergefn
ghsa·2021-08-10
CVE-2021-23417 [MEDIUM] CWE-1321 Prototype Pollution in deepmergefn
Prototype Pollution in deepmergefn
All versions of package deepmergefn are vulnerable to Prototype Pollution via deepMerge function.
GHSA
Remote Code Execution via unsafe classes in otherwise permitted modules
ghsa·2021-08-05
CVE-2021-32807 [MEDIUM] CWE-1321 Remote Code Execution via unsafe classes in otherwise permitted modules
Remote Code Execution via unsafe classes in otherwise permitted modules
### Impact
The module `AccessControl` defines security policies for Python code used in restricted code within Zope applications. Restricted code is any code that resides in Zope's object database, such as the contents of `Script (Python)` objects.
The policies defined in `AccessControl` severely restrict access to Python modules and only exempt a few that are deemed safe, such as Python's `string` module. However, full access to the `string` module also allows access to the class `Formatter`, which can be overridden and extended within `Script (Python)` in a way that provides access to other unsafe Python libraries. Those unsafe Python libraries can be used for remote code execution.
By default, you need to have th
GHSA
Remote Code Execution via Script (Python) objects under Python 3
ghsa·2021-08-05
CVE-2021-32811 [HIGH] CWE-1321 Remote Code Execution via Script (Python) objects under Python 3
Remote Code Execution via Script (Python) objects under Python 3
### Impact
Background: The optional add-on package `Products.PythonScripts` adds `Script (Python)` to the list of content items a user can add to the Zope object database. Inside these scripts users can write Python code that is executed when rendered through the web. The code environment in these script objects is limited, it relies on the `RestrictedPython` package to provide a "safe" subset of Python instructions as well as the `AccessControl` package that defines security policies for execution in the context of a Zope application.
Recently the `AccessControl` package was updated to fix a remote code execution security issue. A link to the security advisory is provided in the References section below. The bug tightens t
GHSA
Prototype Pollution in GraphHopper
ghsa·2021-08-02
CVE-2021-23408 [MEDIUM] CWE-1321 Prototype Pollution in GraphHopper
Prototype Pollution in GraphHopper
This affects the package `com.graphhopper:graphhopper-web-bundle` before 3.2, from 4.0-pre1 and before 4.0. The URL parser could be tricked into adding or modifying properties of Object.prototype using a constructor or __proto__ payload.
GHSA
Prototype Pollution in think-helper
ghsa·2021-07-01
CVE-2021-32736 [HIGH] CWE-1321 Prototype Pollution in think-helper
Prototype Pollution in think-helper
### Impact
The software receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
### Patches
`[email protected]` patched it, anyone used `think-helper` should upgrade to `>=1.1.3` version.
### References
https://cwe.mitre.org/data/definitions/1321.html
### For more information
If you have any questions or comments about this advisory:
* Open an issue in [thinkjs/thinkjs](https://github.com/thinkjs/thinkjs)
* Email us at [[email protected]](mailto:[email protected])
GHSA
Prototype pollution in safe-flat
ghsa·2021-06-21
CVE-2021-25927 [CRITICAL] CWE-1321 Prototype pollution in safe-flat
Prototype pollution in safe-flat
Prototype pollution vulnerability in 'safe-flat' versions 2.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
GHSA
Prototype Pollution in lutils
ghsa·2021-06-21
CVE-2021-23396 [MEDIUM] CWE-1321 Prototype Pollution in lutils
Prototype Pollution in lutils
All versions of package lutils are vulnerable to Prototype Pollution via the main (merge) function.
GHSA
Prototype pollution in nconf-toml
ghsa·2021-06-07
CVE-2021-25946 [CRITICAL] CWE-1321 Prototype pollution in nconf-toml
Prototype pollution in nconf-toml
Prototype pollution vulnerability in `nconf-toml` versions 0.0.1 through 0.0.2 allows an attacker to cause a denial of service and may lead to remote code execution.
GHSA
Prototype pollution in Merge-deep
ghsa·2021-06-07
CVE-2021-26707 [CRITICAL] CWE-1321 Prototype pollution in Merge-deep
Prototype pollution in Merge-deep
The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library.
GHSA
Prototype Pollution in deep-override
ghsa·2021-05-17
CVE-2021-25941 [CRITICAL] CWE-1321 Prototype Pollution in deep-override
Prototype Pollution in deep-override
Prototype pollution vulnerability in 'deep-override' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
GHSA
Autobinding vulnerability in MITREid Connect
ghsa·2021-05-13
CVE-2021-27582 [CRITICAL] CWE-1321 Autobinding vulnerability in MITREid Connect
Autobinding vulnerability in MITREid Connect
org/mitre/oauth2/web/OAuthConfirmationController.java in the OpenID Connect server implementation for MITREid Connect through 1.3.3 contains a Mass Assignment (aka Autobinding) vulnerability. This arises due to unsafe usage of the @ModelAttribute annotation during the OAuth authorization flow, in which HTTP request parameters affect an authorizationRequest.
GHSA
Prototype Pollution in iniparserjs
ghsa·2021-04-13
CVE-2021-23328 [MEDIUM] CWE-1321 Prototype Pollution in iniparserjs
Prototype Pollution in iniparserjs
This affects all versions of package iniparserjs. This vulnerability relates when ini_parser.js is concentrating arrays. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.
GHSA
Prototype Pollution Vulnerability in object-collider
ghsa·2021-03-19
CVE-2021-25914 [CRITICAL] CWE-1321 Prototype Pollution Vulnerability in object-collider
Prototype Pollution Vulnerability in object-collider
Prototype pollution vulnerability in 'object-collider' versions 1.0.0 through 1.0.3 allows attacker to cause a denial of service and may lead to remote code execution.
GHSA
Prototype Pollution in Node-Red
ghsa·2021-02-26
CVE-2021-21297 [HIGH] CWE-1321 Prototype Pollution in Node-Red
Prototype Pollution in Node-Red
### Impact
Node-RED 1.2.7 and earlier contains a Prototype Pollution vulnerability in the admin API. A badly formed request can modify the prototype of the default JavaScript Object with the potential to affect the default behaviour of the Node-RED runtime.
### Patches
The vulnerability is patched in the 1.2.8 release.
### Workarounds
A workaround is to ensure only authorised users are able to access the editor url.
### For more information
If you have any questions or comments about this advisory:
* Email us at [[email protected]](mailto:[email protected])
### Acknowledgements
Thanks to the Tencent Woodpecker Security Team for disclosing this vulnerability.
GHSA
Prototype Pollution in Dynamoose
ghsa·2021-02-08
CVE-2021-21304 [HIGH] CWE-1321 Prototype Pollution in Dynamoose
Prototype Pollution in Dynamoose
### Impact
In Dynamoose versions 2.0.0-2.6.0 there was a prototype pollution vulnerability in the internal utility method [`lib/utils/object/set.ts`](https://github.com/dynamoose/dynamoose/blob/master/lib/utils/object/set.ts). This method is used throughout the codebase for various operations throughout Dynamoose.
We have not seen any evidence of this vulnerability being exploited.
We do not believe this issue impacts v1.x.x since this method was added as part of the v2 rewrite. This vulnerability also impacts v2.x.x beta/alpha versions.
### Patches
v2.7.0 includes a patch for this vulnerability.
### Workarounds
We are unaware of any workarounds to patch this vulnerability other than upgrading to v2.7.0 or greater.
### References
- Patch commit ha
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-02-04
Published