Lucene search

K
cvelistMitreCVELIST:CVE-2021-28860
HistoryMay 03, 2021 - 11:48 a.m.

CVE-2021-28860

2021-05-0311:48:33
mitre
www.cve.org
2
node.js
mixme
object manipulation
dos
vulnerability
cve-2021-28860

AI Score

9.2

Confidence

High

EPSS

0.01

Percentile

83.6%

In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via ‘proto’ through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at risk causing a potential denial of service (DoS).

AI Score

9.2

Confidence

High

EPSS

0.01

Percentile

83.6%

Related for CVELIST:CVE-2021-28860