CVE-2024-38996: Critical severity ag-grid vulnerability
ag-grid-community v31.3.2 and ag-grid-enterprise v31.3.2 were discovered to contain a prototype pollution via the .mergeDeep function. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38996?
CVE-2024-38996 is a high severity vulnerability due to the potential for arbitrary code execution and Denial of Service.
How do I fix CVE-2024-38996?
To fix CVE-2024-38996, update ag-grid-community and ag-grid-enterprise to version 31.3.4 or higher.
Which versions are affected by CVE-2024-38996?
CVE-2024-38996 affects ag-grid-community v31.3.2 and ag-grid-enterprise v31.3.2.
What impact does CVE-2024-38996 have?
CVE-2024-38996 allows attackers to execute arbitrary code or cause a Denial of Service through prototype pollution.
Is there a patch available for CVE-2024-38996?
Yes, upgrading to version 31.3.4 of ag-grid-community or ag-grid-enterprise resolves CVE-2024-38996.