CVE-2021-3918
published 2021-11-13CVE-2021-3918: json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
PriorityP346critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.56%
88.2th percentile
json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | node-json-schema | < node-json-schema 0.4.0+~7.0.9-1 (bookworm) | node-json-schema 0.4.0+~7.0.9-1 (bookworm) |
| json-schema_project | json-schema | < 0.4.0 | 0.4.0 |
| json-schema_project | json-schema | >= 0 < 0.4.0 | 0.4.0 |
| kriszyp | kriszyp_json-schema | unspecified – 0.3.0 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
JSON Schema vulnerability
vendor_ubuntu·2023-05-24
CVE-2021-3918 JSON Schema vulnerability
Title: JSON Schema vulnerability
Summary: JSON Schema could be made to crash or run programs if it opened specially
crafted input.
It was discovered that JSON Schema incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to exploit
JavaScript runtimes and cause a denial of service or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle PeopleSoft Risk Matrix: Chatbot Framework (JSON Schema) — CVE-2021-3918
vendor_oracle·2023-01-15·CVSS 9.8
CVE-2021-3918 [CRITICAL] Oracle Oracle PeopleSoft Risk Matrix: Chatbot Framework (JSON Schema) — CVE-2021-3918
Oracle Oracle PeopleSoft Risk Matrix: Chatbot Framework (JSON Schema) vulnerability
CVE: CVE-2021-3918
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Oracle
Oracle Oracle Communications Applications Risk Matrix: REST API (json-schema) — CVE-2021-3918
vendor_oracle·2022-10-15·CVSS 9.8
CVE-2021-3918 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: REST API (json-schema) — CVE-2021-3918
Oracle Oracle Communications Applications Risk Matrix: REST API (json-schema) vulnerability
CVE: CVE-2021-3918
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Red Hat
nodejs-json-schema: Prototype pollution vulnerability
vendor_redhat·2021-10-03·CVSS 9.8
CVE-2021-3918 [CRITICAL] CWE-915 nodejs-json-schema: Prototype pollution vulnerability
nodejs-json-schema: Prototype pollution vulnerability
json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
The json-schema Node.JS library was vulnerable to prototype pollution during the validation of a JSON object. An attacker, able to provide a specially crafted JSON file for validation, could use this flaw to modify the behavior of the node program, to, for example, execute arbitrary code.
Statement: npm versions 8.0.0 and older provide a vulnerable version of the json-schema library. However, it is currently believed that in the context of npm, it is not possible to take advantage of the vulnerability.
Red Hat Enterprise Linux version 8 and Software Collections provide a vulnerable version of the json-schema library
Debian
CVE-2021-3918: node-json-schema - json-schema is vulnerable to Improperly Controlled Modification of Object Protot...
vendor_debian·2021·CVSS 9.8
CVE-2021-3918 [CRITICAL] CVE-2021-3918: node-json-schema - json-schema is vulnerable to Improperly Controlled Modification of Object Protot...
json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Scope: local
bookworm: resolved (fixed in 0.4.0+~7.0.9-1)
bullseye: resolved (fixed in 0.3.0+~7.0.6-1+deb11u1)
forky: resolved (fixed in 0.4.0+~7.0.9-1)
sid: resolved (fixed in 0.4.0+~7.0.9-1)
trixie: resolved (fixed in 0.4.0+~7.0.9-1)
OSV
json-schema is vulnerable to Prototype Pollution
osv·2021-11-19
CVE-2021-3918 [CRITICAL] json-schema is vulnerable to Prototype Pollution
json-schema is vulnerable to Prototype Pollution
json-schema before version 0.4.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution').
GHSA
json-schema is vulnerable to Prototype Pollution
ghsa·2021-11-19
CVE-2021-3918 [CRITICAL] CWE-1321 json-schema is vulnerable to Prototype Pollution
json-schema is vulnerable to Prototype Pollution
json-schema before version 0.4.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution').
OSV
CVE-2021-3918: json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
osv·2021-11-13·CVSS 9.8
CVE-2021-3918 [CRITICAL] CVE-2021-3918: json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/kriszyp/json-schema/commit/22f146111f541d9737e832823699ad3528ca7741https://huntr.dev/bounties/bb6ccd63-f505-4e3a-b55f-cd2662c261a9https://lists.debian.org/debian-lts-announce/2022/12/msg00013.htmlhttps://github.com/kriszyp/json-schema/commit/22f146111f541d9737e832823699ad3528ca7741https://huntr.dev/bounties/bb6ccd63-f505-4e3a-b55f-cd2662c261a9https://lists.debian.org/debian-lts-announce/2022/12/msg00013.htmlhttps://security.netapp.com/advisory/ntap-20250117-0004/
2021-11-13
Published