CVE-2021-23449

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/10/2021
Last modified:
28/06/2022

Description

This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitrary code on the host machine.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:* 3.9.4 (excluding)