CVE-2021-25913

Prototype pollution vulnerability in 'set-or-get' version 1.0.0 through 1.2.10 allows an attacker to cause a denial of service and may lead to remote code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:set-or-get_project:set-or-get:*:*:*:*:*:node.js:*:*

History

21 Nov 2024, 05:55

Type Values Removed Values Added
References () https://github.com/IonicaBizau/set-or-get.js/commit/82ede5cccb2e8d13e4f62599203a4389f6d8e936 - Patch, Third Party Advisory () https://github.com/IonicaBizau/set-or-get.js/commit/82ede5cccb2e8d13e4f62599203a4389f6d8e936 - Patch, Third Party Advisory
References () https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25913 - Exploit, Third Party Advisory () https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25913 - Exploit, Third Party Advisory

08 Aug 2023, 14:22

Type Values Removed Values Added
CWE NVD-CWE-Other CWE-1321

Information

Published : 2021-02-08 22:15

Updated : 2024-11-21 05:55


NVD link : CVE-2021-25913

Mitre link : CVE-2021-25913

CVE.ORG link : CVE-2021-25913


JSON object : View

Products Affected

set-or-get_project

  • set-or-get
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')