CVE-2021-23434
published 2021-08-27CVE-2021-23434: This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components used in the…
PriorityP345high8.6CVSS 3.1
AVNACLPRNUINSUCLILAH
EPSS
1.90%
77.6th percentile
This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components used in the path parameter are arrays. In particular, the condition currentPath === '__proto__' returns false if currentPath is ['__proto__']. This is because the === operator returns always false when the type of the operands is different.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | node-object-path | < node-object-path 0.11.7-1 (bookworm) | node-object-path 0.11.7-1 (bookworm) |
| object-path_project | object-path | < 0.11.6 | 0.11.6 |
| object-path_project | object-path | >= 0 < 0.11.6 | 0.11.6 |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_debian7.7HIGH
vendor_redhat7.7HIGH
vendor_ubuntu7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
object-path vulnerabilities
vendor_ubuntu·2023-03-22·CVSS 7.7
CVE-2021-3805 [HIGH] object-path vulnerabilities
Title: object-path vulnerabilities
Summary: Several security issues were fixed in object-path.
It was discovered that the set() method in object-path could be corrupted
as a result of prototype pollution by sending a message to the parent
process. An attacker could use this issue to cause object-path to crash.
(CVE-2020-15256, CVE-2021-23434, CVE-2021-3805)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
object-path: Type confusion vulnerability can lead to a bypass of CVE-2020-15256
vendor_redhat·2021-08-27·CVSS 7.7
CVE-2021-23434 [HIGH] CWE-843 object-path: Type confusion vulnerability can lead to a bypass of CVE-2020-15256
object-path: Type confusion vulnerability can lead to a bypass of CVE-2020-15256
This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components used in the path parameter are arrays. In particular, the condition currentPath === '__proto__' returns false if currentPath is ['__proto__']. This is because the === operator returns always false when the type of the operands is different.
Prototype pollution has been discovered in object-path NodeJS library. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components used in the path parameter are arrays. In particular, the condition currentPath === '__proto__' returns false if currentPath is ['__proto__']. This is because the
Debian
CVE-2021-23434: node-object-path - This affects the package object-path before 0.11.6. A type confusion vulnerabili...
vendor_debian·2021·CVSS 7.7
CVE-2021-23434 [HIGH] CVE-2021-23434: node-object-path - This affects the package object-path before 0.11.6. A type confusion vulnerabili...
This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components used in the path parameter are arrays. In particular, the condition currentPath === '__proto__' returns false if currentPath is ['__proto__']. This is because the === operator returns always false when the type of the operands is different.
Scope: local
bookworm: resolved (fixed in 0.11.7-1)
bullseye: resolved (fixed in 0.11.5-3+deb11u1)
forky: resolved (fixed in 0.11.7-1)
sid: resolved (fixed in 0.11.7-1)
trixie: resolved (fixed in 0.11.7-1)
OSV
node-object-path vulnerabilities
osv·2023-03-22·CVSS 9.8
CVE-2020-15256 [CRITICAL] node-object-path vulnerabilities
node-object-path vulnerabilities
It was discovered that the set() method in object-path could be corrupted
as a result of prototype pollution by sending a message to the parent
process. An attacker could use this issue to cause object-path to crash.
(CVE-2020-15256, CVE-2021-23434, CVE-2021-3805)
OSV
Prototype Pollution in object-path
osv·2021-09-01·CVSS 9.8
CVE-2021-23434 [CRITICAL] Prototype Pollution in object-path
Prototype Pollution in object-path
This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components used in the path parameter are arrays. In particular, the condition `currentPath === '__proto__'` returns false if `currentPath` is `['__proto__']`. This is because the `===` operator returns always false when the type of the operands is different.
GHSA
Prototype Pollution in object-path
ghsa·2021-09-01·CVSS 9.8
CVE-2021-23434 [CRITICAL] CWE-1321 Prototype Pollution in object-path
Prototype Pollution in object-path
This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components used in the path parameter are arrays. In particular, the condition `currentPath === '__proto__'` returns false if `currentPath` is `['__proto__']`. This is because the `===` operator returns always false when the type of the operands is different.
OSV
CVE-2021-23434: This affects the package object-path before 0
osv·2021-08-27·CVSS 9.8
CVE-2021-23434 [CRITICAL] CVE-2021-23434: This affects the package object-path before 0
This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components used in the path parameter are arrays. In particular, the condition currentPath === '__proto__' returns false if currentPath is ['__proto__']. This is because the === operator returns always false when the type of the operands is different.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/mariocasciaro/object-path%230116https://github.com/mariocasciaro/object-path/commit/7bdf4abefd102d16c163d633e8994ef154cab9ebhttps://lists.debian.org/debian-lts-announce/2023/01/msg00031.htmlhttps://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1570423https://snyk.io/vuln/SNYK-JS-OBJECTPATH-1569453https://github.com/mariocasciaro/object-path%230116https://github.com/mariocasciaro/object-path/commit/7bdf4abefd102d16c163d633e8994ef154cab9ebhttps://lists.debian.org/debian-lts-announce/2023/01/msg00031.htmlhttps://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1570423https://snyk.io/vuln/SNYK-JS-OBJECTPATH-1569453
2021-08-27
Published