Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34489
HistoryMar 03, 2022 - 6:24 a.m.

Prototype Pollution

2022-03-0306:24:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
prototype pollution
jquery.cookie
removecookie function
vulnerability

EPSS

0.001

Percentile

30.0%

jquery.cookie is vulnerable to prototype pollution. An attacker can inject properties into existing construct prototypes via the key parameter in the removeCookie function of jquery.cookie.js and modify attributes such as __proto__, constructor, and prototype.