Prototype pollution vulnerability in 'object-collider' versions 1.0.0 through 1.0.3 allows attacker to cause a denial of service and may lead to remote code execution.
References
Link | Resource |
---|---|
https://github.com/FireBlinkLTD/object-collider/commit/321f75a7f8e7b3393e5b7dd6dd9ab26ede5906e5 | Patch Third Party Advisory |
https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25914 | Exploit Third Party Advisory |
Configurations
History
08 Aug 2023, 14:22
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-1321 |
Information
Published : 2021-03-01 18:15
Updated : 2024-02-28 18:08
NVD link : CVE-2021-25914
Mitre link : CVE-2021-25914
CVE.ORG link : CVE-2021-25914
JSON object : View
Products Affected
fireblink
- object-collider
CWE
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')