Количество 2
Количество 2

CVE-2024-21505
Versions of the package web3-utils before 4.2.1 are vulnerable to Prototype Pollution via the utility functions format and mergeDeep, due to insecure recursive merge. An attacker can manipulate an object's prototype, potentially leading to the alteration of the behavior of all objects inheriting from the affected prototype by passing specially crafted input to these functions.
GHSA-2g4c-8fpm-c46v
web3-utils Prototype Pollution vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2024-21505 Versions of the package web3-utils before 4.2.1 are vulnerable to Prototype Pollution via the utility functions format and mergeDeep, due to insecure recursive merge. An attacker can manipulate an object's prototype, potentially leading to the alteration of the behavior of all objects inheriting from the affected prototype by passing specially crafted input to these functions. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад |
GHSA-2g4c-8fpm-c46v web3-utils Prototype Pollution vulnerability | CVSS3: 7.5 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу