First published: Mon Oct 18 2021(Updated: )
This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitrary code on the host machine.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Vm2 Project | <3.9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23449 is considered a critical vulnerability that allows for arbitrary code execution due to prototype pollution.
To mitigate CVE-2021-23449, you should upgrade the vm2 package to version 3.9.4 or later.
All versions of vm2 prior to 3.9.4 are affected by CVE-2021-23449.
CVE-2021-23449 is associated with a Prototype Pollution attack vector.
Yes, CVE-2021-23449 can potentially lead to data breaches by enabling arbitrary code execution on the host machine.