Логотип exploitDog
bind:CVE-2021-21304
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-21304

Количество 2

Количество 2

nvd логотип

CVE-2021-21304

около 5 лет назад

Dynamoose is an open-source modeling tool for Amazon's DynamoDB. In Dynamoose from version 2.0.0 and before version 2.7.0 there was a prototype pollution vulnerability in the internal utility method "lib/utils/object/set.ts". This method is used throughout the codebase for various operations throughout Dynamoose. We have not seen any evidence of this vulnerability being exploited. There is no evidence this vulnerability impacts versions 1.x.x since the vulnerable method was added as part of the v2 rewrite. This vulnerability also impacts v2.x.x beta/alpha versions. Version 2.7.0 includes a patch for this vulnerability.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-rrqm-p222-8ph2

около 5 лет назад

Prototype Pollution in Dynamoose

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-21304

Dynamoose is an open-source modeling tool for Amazon's DynamoDB. In Dynamoose from version 2.0.0 and before version 2.7.0 there was a prototype pollution vulnerability in the internal utility method "lib/utils/object/set.ts". This method is used throughout the codebase for various operations throughout Dynamoose. We have not seen any evidence of this vulnerability being exploited. There is no evidence this vulnerability impacts versions 1.x.x since the vulnerable method was added as part of the v2 rewrite. This vulnerability also impacts v2.x.x beta/alpha versions. Version 2.7.0 includes a patch for this vulnerability.

CVSS3: 7.2
1%
Низкий
около 5 лет назад
github логотип
GHSA-rrqm-p222-8ph2

Prototype Pollution in Dynamoose

CVSS3: 7.2
1%
Низкий
около 5 лет назад

Уязвимостей на страницу