Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-23497: Prototype Pollution in @strikeentco/set | CVE-2021-23497 | Snyk

This affects the package @strikeentco/set before 1.0.2. It allows an attacker to cause a denial of service and may lead to remote code execution.

Note: This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-STRIKEENTCOSET-1038821

CVE
#vulnerability#dos#js
  • Attack Complexity

    Low

  • Availability

    High

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

  • snyk-id

    SNYK-JS-STRIKEENTCOSET-2385945

  • published

    31 Jan 2022

  • disclosed

    27 Jan 2022

  • credit

    P.Adithya Srinivas, Masudul Hasan Masud Bhuiyan, Cristian-Alexandru Staicu

How to fix?

Overview

Details

Types of attacks

Affected environments

How to prevent

References

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907