CVE-2024-45435

Chartist 1.x through 1.3.0 allows Prototype Pollution via the extend function.
Configurations

Configuration 1 (hide)

cpe:2.3:a:chartist:chartist:*:*:*:*:*:node.js:*:*

History

03 Sep 2024, 17:23

Type Values Removed Values Added
CPE cpe:2.3:a:chartist:chartist:*:*:*:*:*:*:*:* cpe:2.3:a:chartist:chartist:*:*:*:*:*:node.js:*:*

30 Aug 2024, 16:05

Type Values Removed Values Added
First Time Chartist
Chartist chartist
References () https://gist.github.com/tariqhawis/c67177164d3b7975210caddb25b60d62 - () https://gist.github.com/tariqhawis/c67177164d3b7975210caddb25b60d62 - Exploit
References () https://github.com/chartist-js/chartist/issues/1427 - () https://github.com/chartist-js/chartist/issues/1427 - Issue Tracking
CPE cpe:2.3:a:chartist:chartist:*:*:*:*:*:*:*:*

29 Aug 2024, 20:37

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-1321

29 Aug 2024, 13:25

Type Values Removed Values Added
Summary
  • (es) Chartist 1.x a 1.3.0 permite la contaminación de prototipos a través de la función de extensión.

29 Aug 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-29 03:15

Updated : 2024-09-03 17:23


NVD link : CVE-2024-45435

Mitre link : CVE-2024-45435

CVE.ORG link : CVE-2024-45435


JSON object : View

Products Affected

chartist

  • chartist
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')