Vulnerability Details CVE-2021-28860
In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at risk causing a potential denial of service (DoS).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 77.7%
CVSS Severity
CVSS v3 Score 9.1
CVSS v2 Score 6.4
Products affected by CVE-2021-28860
-
cpe:2.3:a:adaltas:mixme:-
-
cpe:2.3:a:adaltas:mixme:0.0.1
-
cpe:2.3:a:adaltas:mixme:0.1.0
-
cpe:2.3:a:adaltas:mixme:0.2.0
-
cpe:2.3:a:adaltas:mixme:0.3.0
-
cpe:2.3:a:adaltas:mixme:0.3.1
-
cpe:2.3:a:adaltas:mixme:0.3.2
-
cpe:2.3:a:adaltas:mixme:0.3.3
-
cpe:2.3:a:adaltas:mixme:0.3.5
-
cpe:2.3:a:adaltas:mixme:0.4.0
-
cpe:2.3:a:adaltas:mixme:0.5.0