CVE-2021-23460: Prototype Pollution
Impact
The set method is vulnerable to prototype pollution with specially crafted inputs.
javascript // insert the following into poc.js and run node poc,js (after installing the package) let parser = require("min-dash"); parser.set({}, [["proto"], "polluted"], "success"); console.log(polluted);
Patches
min-dash>=3.8.1 fix the issue.
Workarounds
No workarounds exist for the issue.
References
Closed via https://github.com/bpmn-io/min-dash/pull/21.
Credits
Credits to Cristian-Alexandru STAICU who found the vulnerability and to Idan Digmi from the Snyk Security Team who reported the vulnerability to us, responsibly.
Other sources
The package min-dash before 3.8.1 are vulnerable to Prototype Pollution via the set method due to missing enforcement of key types.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-23460?
CVE-2021-23460 is considered a moderate severity vulnerability due to its potential for causing prototype pollution.
How do I fix CVE-2021-23460?
To fix CVE-2021-23460, update the min-dash package to version 3.8.1 or later.
What kind of systems are affected by CVE-2021-23460?
CVE-2021-23460 affects applications using versions of the min-dash package prior to 3.8.1.
What does prototype pollution mean in the context of CVE-2021-23460?
In the context of CVE-2021-23460, prototype pollution allows an attacker to manipulate the prototype of built-in objects, potentially leading to security issues.
Is CVE-2021-23460 exploitable in production environments?
Yes, CVE-2021-23460 is exploitable in production environments if vulnerable versions of min-dash are being utilized.