Логотип exploitDog
bind:CVE-2021-41097
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-41097

Количество 2

Количество 2

nvd логотип

CVE-2021-41097

больше 4 лет назад

aurelia-path is part of the Aurelia platform and contains utilities for path manipulation. There is a prototype pollution vulnerability in aurelia-path before version 1.1.7. The vulnerability exposes Aurelia application that uses `aurelia-path` package to parse a string. The majority of this will be Aurelia applications that employ the `aurelia-router` package. An example is this could allow an attacker to change the prototype of base object class `Object` by tricking an application to parse the following URL: `https://aurelia.io/blog/?__proto__[asdf]=asdf`. The problem is patched in version `1.1.7`.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3c9c-2p65-qvwv

больше 4 лет назад

Prototype pollution in aurelia-path

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-41097

aurelia-path is part of the Aurelia platform and contains utilities for path manipulation. There is a prototype pollution vulnerability in aurelia-path before version 1.1.7. The vulnerability exposes Aurelia application that uses `aurelia-path` package to parse a string. The majority of this will be Aurelia applications that employ the `aurelia-router` package. An example is this could allow an attacker to change the prototype of base object class `Object` by tricking an application to parse the following URL: `https://aurelia.io/blog/?__proto__[asdf]=asdf`. The problem is patched in version `1.1.7`.

CVSS3: 9.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3c9c-2p65-qvwv

Prototype pollution in aurelia-path

CVSS3: 9.1
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу