Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-21505

Опубликовано: 25 мар. 2024
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Versions of the package web3-utils before 4.2.1 are vulnerable to Prototype Pollution via the utility functions format and mergeDeep, due to insecure recursive merge. An attacker can manipulate an object's prototype, potentially leading to the alteration of the behavior of all objects inheriting from the affected prototype by passing specially crafted input to these functions.

EPSS

Процентиль: 19%
0.00062
Низкий

7.5 High

CVSS3

Дефекты

CWE-1321
CWE-1321

Связанные уязвимости

CVSS3: 7.5
github
больше 1 года назад

web3-utils Prototype Pollution vulnerability

EPSS

Процентиль: 19%
0.00062
Низкий

7.5 High

CVSS3

Дефекты

CWE-1321
CWE-1321