First published: Fri Feb 04 2022(Updated: )
This affects the package @strikeentco/set before 1.0.2. It allows an attacker to cause a denial of service and may lead to remote code execution. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-STRIKEENTCOSET-1038821
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Set-value Project | <1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23497 is classified as a critical vulnerability due to its potential to cause denial of service and remote code execution.
To fix CVE-2021-23497, upgrade the package @strikeentco/set to version 1.0.2 or later.
CVE-2021-23497 is caused by an incomplete fix which allows for type confusion leading to denial of service.
CVE-2021-23497 affects versions of the package @strikeentco/set prior to 1.0.2.
Yes, CVE-2021-23497 can potentially lead to remote code execution, making it exploitable remotely.