CVE Vulnerabilities

CVE-2021-23432

Published: Aug 24, 2021 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge()

Affected Software

NameVendorStart VersionEnd Version
MootoolsMootools_project**
MootoolsUbuntubionic*
MootoolsUbuntufocal*
MootoolsUbuntuhirsute*
MootoolsUbuntuimpish*
MootoolsUbuntukinetic*
MootoolsUbuntulunar*
MootoolsUbuntumantic*
MootoolsUbuntuoracular*
MootoolsUbuntuplucky*
MootoolsUbuntutrusty*
MootoolsUbuntuxenial*

References