Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40976
HistoryJun 21, 2023 - 10:43 a.m.

Prototype Pollution

2023-06-2110:43:10
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
vulnerability
extend function
utils.js
attacker
inject
modify
malicious properties
__proto__
prototype pollution
software

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

57.4%

progressbar.js is vulnerable to Prototype Pollution. The vulnerability exists in extend function at utils.js which allows an attacker to inject and modify malicious properties such as __proto__, resulting in prototype pollution.

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

57.4%

Related for VERACODE:40976