← back
CVE-2021-23438

Prototype Pollution

CVSS 5.6 MEDIUMEPSS 1.7%
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.6EPSS 1.7%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
01 Sep 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
This affects the package mpath before 0.8.4. A type confusion vulnerability can lead to a bypass of CVE-2018-16490. In particular, the condition ignoreProperties.indexOf(parts[i]) !== -1 returns -1 if parts[i] is ['__proto__']. This is because the method that has been called if the input is an array is Array.prototype.indexOf() and not String.prototype.indexOf(). They behave differently depending on the type of the input.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
Affected products
n/a · mpath

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →