First published: Fri Apr 23 2021(Updated: )
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-bbq 1.2.1 allows a malicious user to inject properties into Object.prototype.
Credit: vulnreport@tenable.com vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jquery-bbq Project Jquery-bbq | =1.2.1 | |
IBM Cognos Analytics | <=12.0.0-12.0.2 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-20086 is high with a severity value of 8.8.
CVE-2021-20086 is a vulnerability that allows a malicious user to inject properties into Object.prototype through improperly controlled modification of object prototype attributes, also known as 'Prototype Pollution'.
CVE-2021-20086 affects jquery-bbq version 1.2.1.
To fix CVE-2021-20086, update jquery-bbq to a version that has patched the vulnerability.
More information about CVE-2021-20086 can be found at the following reference: [https://github.com/BlackFan/client-side-prototype-pollution/blob/master/pp/jquery-bbq.md](https://github.com/BlackFan/client-side-prototype-pollution/blob/master/pp/jquery-bbq.md)