CVE-2021-3805
published 2021-09-17CVE-2021-3805: object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.10%
79.8th percentile
object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | node-object-path | < node-object-path 0.11.8-1 (bookworm) | node-object-path 0.11.8-1 (bookworm) |
| mariocasciaro | mariocasciaro_object-path | >= unspecified < 0.11.8 | 0.11.8 |
| object-path_project | object-path | < 0.11.8 | 0.11.8 |
| object-path_project | object-path | >= 0 < 0.11.8 | 0.11.8 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv9.8CRITICAL
vendor_ubuntu7.7HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
object-path vulnerabilities
vendor_ubuntu·2023-03-22·CVSS 7.7
CVE-2021-3805 [HIGH] object-path vulnerabilities
Title: object-path vulnerabilities
Summary: Several security issues were fixed in object-path.
It was discovered that the set() method in object-path could be corrupted
as a result of prototype pollution by sending a message to the parent
process. An attacker could use this issue to cause object-path to crash.
(CVE-2020-15256, CVE-2021-23434, CVE-2021-3805)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
nodejs-object-path: prototype pollution vulnerability
vendor_redhat·2021-09-13·CVSS 7.5
CVE-2021-3805 [HIGH] CWE-915 nodejs-object-path: prototype pollution vulnerability
nodejs-object-path: prototype pollution vulnerability
object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
A flaw was found in the object-path nodejs library when the del() function is called to validate object properties. An attacker can manipulate or alter the prototype of an object causing the modification of default properties on all objects. This could lead into a service disruption or a denial of service attack (DoS).
Package: servicemesh-prometheus (OpenShift Service Mesh 1) - Out of support scope
Package: servicemesh-prometheus (OpenShift Service Mesh 2.0) - Affected
Package: rhacm2/application-ui-rhel8 (Red Hat Advanced Cluster Management for Kubernetes 2) - Not affected
Package: rhacm2/console-api-rhel8 (Red
Debian
CVE-2021-3805: node-object-path - object-path is vulnerable to Improperly Controlled Modification of Object Protot...
vendor_debian·2021·CVSS 7.5
CVE-2021-3805 [HIGH] CVE-2021-3805: node-object-path - object-path is vulnerable to Improperly Controlled Modification of Object Protot...
object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Scope: local
bookworm: resolved (fixed in 0.11.8-1)
bullseye: resolved (fixed in 0.11.5-3+deb11u1)
forky: resolved (fixed in 0.11.8-1)
sid: resolved (fixed in 0.11.8-1)
trixie: resolved (fixed in 0.11.8-1)
OSV
node-object-path vulnerabilities
osv·2023-03-22·CVSS 9.8
CVE-2020-15256 [CRITICAL] node-object-path vulnerabilities
node-object-path vulnerabilities
It was discovered that the set() method in object-path could be corrupted
as a result of prototype pollution by sending a message to the parent
process. An attacker could use this issue to cause object-path to crash.
(CVE-2020-15256, CVE-2021-23434, CVE-2021-3805)
OSV
Prototype Pollution in object-path
osv·2021-09-20
CVE-2021-3805 [HIGH] Prototype Pollution in object-path
Prototype Pollution in object-path
object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'). The `del()` function fails to validate which Object properties it deletes. This allows attackers to modify the prototype of Object, causing the modification of default properties like `toString` on all objects.
GHSA
Prototype Pollution in object-path
ghsa·2021-09-20
CVE-2021-3805 [HIGH] CWE-1321 Prototype Pollution in object-path
Prototype Pollution in object-path
object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'). The `del()` function fails to validate which Object properties it deletes. This allows attackers to modify the prototype of Object, causing the modification of default properties like `toString` on all objects.
OSV
CVE-2021-3805: object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
osv·2021-09-17·CVSS 7.5
CVE-2021-3805 [HIGH] CVE-2021-3805: object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/mariocasciaro/object-path/commit/e6bb638ffdd431176701b3e9024f80050d0ef0a6https://huntr.dev/bounties/571e3baf-7c46-46e3-9003-ba7e4e623053https://lists.debian.org/debian-lts-announce/2023/01/msg00031.htmlhttps://github.com/mariocasciaro/object-path/commit/e6bb638ffdd431176701b3e9024f80050d0ef0a6https://huntr.dev/bounties/571e3baf-7c46-46e3-9003-ba7e4e623053https://lists.debian.org/debian-lts-announce/2023/01/msg00031.html
2021-09-17
Published