CVE-2021-23518
published 2022-01-21CVE-2021-23518: The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in…
PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.94%
78.1th percentile
The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using the origin path as __proto__, the attribute of the object is accessed instead of a path. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-72573
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cached-path-relative_project | cached-path-relative | < 1.1.0 | 1.1.0 |
| cached-path-relative_project | cached-path-relative | >= 0 < 1.1.0 | 1.1.0 |
| cached-path-relative_project | cached-path-relative | >= unspecified < 1.1.0 | 1.1.0 |
| debian | debian_linux | — | — |
| debian | node-cached-path-relative | < node-cached-path-relative 1.1.0+~1.0.0-1 (bookworm) | node-cached-path-relative 1.1.0+~1.0.0-1 (bookworm) |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cached-path-relative: Prototype Pollution via the cache variable
vendor_redhat·2022-01-21·CVSS 7.3
CVE-2021-23518 [HIGH] CWE-915 cached-path-relative: Prototype Pollution via the cache variable
cached-path-relative: Prototype Pollution via the cache variable
The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using the origin path as __proto__, the attribute of the object is accessed instead of a path. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-72573
A prototype pollution vulnerability was discovered in cached-path-relative. This flaw allows a remote, unauthenticated attacker to inject a cache variable to leak sensitive information.
Package: rhac
Debian
CVE-2021-23518: node-cached-path-relative - The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollut...
vendor_debian·2021·CVSS 7.3
CVE-2021-23518 [HIGH] CVE-2021-23518: node-cached-path-relative - The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollut...
The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using the origin path as __proto__, the attribute of the object is accessed instead of a path. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-72573
Scope: local
bookworm: resolved (fixed in 1.1.0+~1.0.0-1)
bullseye: resolved (fixed in 1.0.2-1+deb11u1)
forky: resolved (fixed in 1.1.0+~1.0.0-1)
sid: resolved (fixed in 1.1.0+~1.0.0-1)
trixie: resolved (fixed in 1.1.0+~1.0.0-1)
OSV
Prototype Pollution in cached-path-relative
osv·2022-01-27
CVE-2021-23518 [HIGH] Prototype Pollution in cached-path-relative
Prototype Pollution in cached-path-relative
The package cached-path-relative before 1.1.0 is vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using the origin path as __proto__, the attribute of the object is accessed instead of a path. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-72573
GHSA
Prototype Pollution in cached-path-relative
ghsa·2022-01-27
CVE-2021-23518 [HIGH] CWE-1321 Prototype Pollution in cached-path-relative
Prototype Pollution in cached-path-relative
The package cached-path-relative before 1.1.0 is vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using the origin path as __proto__, the attribute of the object is accessed instead of a path. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-72573
OSV
CVE-2021-23518: The package cached-path-relative before 1
osv·2022-01-21·CVSS 9.8
CVE-2021-23518 [CRITICAL] CVE-2021-23518: The package cached-path-relative before 1
The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using the origin path as __proto__, the attribute of the object is accessed instead of a path. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-72573
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/ashaffer/cached-path-relative/commit/40c73bf70c58add5aec7d11e4f36b93d144bb760https://lists.debian.org/debian-lts-announce/2022/12/msg00006.htmlhttps://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2348246https://snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-2342653https://github.com/ashaffer/cached-path-relative/commit/40c73bf70c58add5aec7d11e4f36b93d144bb760https://lists.debian.org/debian-lts-announce/2022/12/msg00006.htmlhttps://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2348246https://snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-2342653
2022-01-21
Published