Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-26707


The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus facilitating prototype-pollution attacks against applications using this library.


Published

2021-06-02T15:15:07.787

Last Modified

2024-11-21T05:56:42.723

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-1321

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application merge-deep_project merge-deep < 3.0.3 Yes
Application netapp e-series_performance_analyzer - Yes

References