CVE-2021-23449

This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitrary code on the host machine.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:*

History

04 Nov 2021, 12:42

Type Values Removed Values Added
References (CONFIRM) https://security.netapp.com/advisory/ntap-20211029-0010/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20211029-0010/ - Third Party Advisory

29 Oct 2021, 13:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20211029-0010/ -

22 Oct 2021, 16:15

Type Values Removed Values Added
Summary This affects the package vm2 before 3.9.4. Prototype Pollution attack vector can lead to sandbox escape and execution of arbitrary code on the host machine. This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitrary code on the host machine.

22 Oct 2021, 14:41

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 7.5
v3 : 10.0
References (MISC) https://snyk.io/vuln/SNYK-JS-VM2-1585918 - (MISC) https://snyk.io/vuln/SNYK-JS-VM2-1585918 - Exploit, Third Party Advisory
References (MISC) https://github.com/patriksimek/vm2/commit/b4f6e2bd2c4a1ef52fc4483d8e35f28bc4481886 - (MISC) https://github.com/patriksimek/vm2/commit/b4f6e2bd2c4a1ef52fc4483d8e35f28bc4481886 - Patch, Third Party Advisory
References (MISC) https://github.com/patriksimek/vm2/issues/363 - (MISC) https://github.com/patriksimek/vm2/issues/363 - Third Party Advisory
References (MISC) https://github.com/patriksimek/vm2/releases/tag/3.9.4 - (MISC) https://github.com/patriksimek/vm2/releases/tag/3.9.4 - Release Notes, Third Party Advisory
CPE cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:*
CWE CWE-915

18 Oct 2021, 17:41

Type Values Removed Values Added
New CVE

Information

Published : 2021-10-18 17:15

Updated : 2024-02-04 22:08


NVD link : CVE-2021-23449

Mitre link : CVE-2021-23449

CVE.ORG link : CVE-2021-23449


JSON object : View

Products Affected

vm2_project

  • vm2
CWE
CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')