CVE-2021-43138Prototype Pollution in Project Async

Severity
7.8HIGHNVD
EPSS
0.7%
top 28.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 6
Latest updateApr 7

Description

In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDasync_project/async3.0.03.2.2+1
npmasync_project/async3.0.03.2.2+1

Also affects: Fedora 36, 37

Patches

🔴Vulnerability Details

2
GHSA
Prototype Pollution in async2022-04-07
OSV
Prototype Pollution in async2022-04-07

📋Vendor Advisories

2
Red Hat
async: Prototype Pollution in async2022-04-07
Debian
CVE-2021-43138: node-async - In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileg...2021
CVE-2021-43138 — Prototype Pollution in Project Async | cvebase