CVE-2024-57069: High severity expand-object vulnerability
Published Feb 5, 2025
·Updated
A prototype pollution in the lib function of expand-object v0.4.2 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
Affected Software
1 affected component
expand-object expand-object
Event History
Feb 5, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-57069?
CVE-2024-57069 has been classified as a high severity vulnerability due to its potential to cause Denial of Service (DoS).
2
How do I fix CVE-2024-57069?
To fix CVE-2024-57069, update the expand-object library to version 0.4.3 or later, where the vulnerability has been addressed.
3
What does CVE-2024-57069 affect?
CVE-2024-57069 affects the lib function of expand-object library version 0.4.2.
4
What type of attack can be executed through CVE-2024-57069?
CVE-2024-57069 can be exploited to perform a Denial of Service (DoS) attack by using a crafted payload.
5
Who is vulnerable to CVE-2024-57069?
Any application using expand-object version 0.4.2 is vulnerable to CVE-2024-57069 unless it has been updated.