Логотип exploitDog
bind:CVE-2024-21505
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-21505

Количество 2

Количество 2

nvd логотип

CVE-2024-21505

почти 2 года назад

Versions of the package web3-utils before 4.2.1 are vulnerable to Prototype Pollution via the utility functions format and mergeDeep, due to insecure recursive merge. An attacker can manipulate an object's prototype, potentially leading to the alteration of the behavior of all objects inheriting from the affected prototype by passing specially crafted input to these functions.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2g4c-8fpm-c46v

почти 2 года назад

web3-utils Prototype Pollution vulnerability

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-21505

Versions of the package web3-utils before 4.2.1 are vulnerable to Prototype Pollution via the utility functions format and mergeDeep, due to insecure recursive merge. An attacker can manipulate an object's prototype, potentially leading to the alteration of the behavior of all objects inheriting from the affected prototype by passing specially crafted input to these functions.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2g4c-8fpm-c46v

web3-utils Prototype Pollution vulnerability

CVSS3: 7.5
0%
Низкий
почти 2 года назад

Уязвимостей на страницу