First published: Tue Aug 24 2021(Updated: )
This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge()
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Array-tools |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23432 is rated as a high severity vulnerability due to its potential impact on affected systems.
To fix CVE-2021-23432, upgrade to a version of Mootools that addresses the vulnerability.
All versions of Mootools are affected by CVE-2021-23432.
The main issue related to CVE-2021-23432 is the ability to pass untrusted input to Object.merge(), leading to potential exploits.
To determine if your application is vulnerable to CVE-2021-23432, check if it uses any version of Mootools.