First published: Fri Dec 24 2021(Updated: )
All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn and the set functions. This is an incomplete fix of [CVE-2020-28442](https://snyk.io/vuln/SNYK-JS-JSDATA-1023655).
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Math.js | <3.0.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23574 is classified as a moderate severity vulnerability.
To fix CVE-2021-23574, you should upgrade to version 3.0.11 or later of the js-data package.
CVE-2021-23574 affects all versions of js-data prior to 3.0.11.
Prototype Pollution allows an attacker to modify an object's prototype, potentially leading to application-level vulnerabilities.
Yes, CVE-2021-23574 is an incomplete fix for CVE-2020-28442.