Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to missing check if the attribute resolves to the object prototype.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Oct 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat rhel Aus Redhat rhel E4s Redhat rhel Tus |
|
| CPEs | cpe:/a:redhat:rhel_aus:8.4 cpe:/a:redhat:rhel_e4s:8.4 cpe:/a:redhat:rhel_tus:8.4 |
|
| Vendors & Products |
Redhat
Redhat rhel Aus Redhat rhel E4s Redhat rhel Tus |
Mon, 07 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Leeoniya
Leeoniya uplot |
|
| CPEs | cpe:2.3:a:leeoniya:uplot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Prototype Pollution
Prototype Pollution uplot |
Leeoniya
Leeoniya uplot |
Tue, 01 Oct 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Prototype Pollution
Prototype Pollution uplot |
|
| CPEs | cpe:2.3:a:prototype_pollution:uplot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Prototype Pollution
Prototype Pollution uplot |
|
| Metrics |
ssvc
|
Tue, 01 Oct 2024 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | uplot: Prototype Pollution in uplot | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 01 Oct 2024 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to missing check if the attribute resolves to the object prototype. | |
| Weaknesses | CWE-1321 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: snyk
Published: 2024-10-01T05:00:02.644Z
Updated: 2024-10-07T14:08:35.115Z
Reserved: 2023-12-22T12:33:20.118Z
Link: CVE-2024-21489
Updated: 2024-10-01T13:55:39.909Z
Status : Awaiting Analysis
Published: 2024-10-01T05:15:12.227
Modified: 2024-10-04T13:51:25.567
Link: CVE-2024-21489