CVE-2021-42581
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/05/2022
Last modified:
04/08/2024
Description
Prototype poisoning in function mapObjIndexed in Ramda 0.27.0 and earlier allows attackers to compromise integrity or availability of application via supplying a crafted object (that contains an own property "__proto__") as an argument to the function. NOTE: the vendor disputes this because the observed behavior only means that a user can create objects that the user didn't know would contain custom prototypes
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Base Score 2.0
6.40
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ramdajs:ramda:*:*:*:*:*:*:*:* | 0.27.0 (including) |
To consult the complete list of CPE names with products and versions, see this page



