CVE-2024-39001: Medium severity ag-grid vulnerability
ag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component ModuleSupport.jsonApply. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39001?
CVE-2024-39001 is considered a high severity vulnerability due to its potential for code execution and denial of service.
How do I fix CVE-2024-39001?
To mitigate CVE-2024-39001, update to ag-grid-enterprise, ag-grid-community, or @ag-grid-enterprise/charts version 31.3.4 or later, or 32.0.1.
What causes the CVE-2024-39001 vulnerability?
CVE-2024-39001 is caused by prototype pollution via the _ModuleSupport.jsonApply component allowing arbitrary property injection.
Which versions are affected by CVE-2024-39001?
CVE-2024-39001 affects ag-grid-enterprise, ag-grid-community, and @ag-grid-enterprise/charts versions prior to 31.3.4 and 32.0.0.
Can CVE-2024-39001 lead to data loss?
Yes, CVE-2024-39001 can potentially lead to data loss through unauthorized code execution or service interruption.