Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40975
HistoryJun 21, 2023 - 10:30 a.m.

Prototype Pollution

2023-06-2110:30:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
vulnerable
fast-xml-parser
prototype pollution
denial of service
remote code execution
privilege escalation

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

27.5%

fast-xml-parser is vulnerable to Prototype Pollution. This vulnerability is due to not sanitizing user input or the proto field leading to polluting the global prototype object which can be used to mount denial of service (DoS), RCE (Remote Code Execution ), Privilege Escalation Attacks.

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

27.5%

Related for VERACODE:40975