Lucene search

K
osvGoogleOSV:CVE-2021-43138
HistoryApr 06, 2022 - 5:15 p.m.

CVE-2021-43138

2022-04-0617:15:08
Google
osv.dev
18
async library
privilege escalation
prototype pollution

AI Score

7.6

Confidence

High

EPSS

0.002

Percentile

54.3%

In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution.

AI Score

7.6

Confidence

High

EPSS

0.002

Percentile

54.3%