CVE-2021-28860

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/05/2021
Last modified:
14/02/2024

Description

In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at risk causing a potential denial of service (DoS).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:adaltas:mixme:*:*:*:*:*:node.js:*:* 0.5.1 (excluding)