CVE-2021-23497: Prototype Pollution
This affects the package @strikeentco/set before 1.0.2. It allows an attacker to cause a denial of service and may lead to remote code execution. Note: This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-STRIKEENTCOSET-1038821
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-23497?
CVE-2021-23497 is classified as a critical vulnerability due to its potential to cause denial of service and remote code execution.
How do I fix CVE-2021-23497?
To fix CVE-2021-23497, upgrade the package @strikeentco/set to version 1.0.2 or later.
What causes CVE-2021-23497?
CVE-2021-23497 is caused by an incomplete fix which allows for type confusion leading to denial of service.
What systems are affected by CVE-2021-23497?
CVE-2021-23497 affects versions of the package @strikeentco/set prior to 1.0.2.
Can CVE-2021-23497 be exploited remotely?
Yes, CVE-2021-23497 can potentially lead to remote code execution, making it exploitable remotely.