CVE Vulnerabilities

CVE-2024-21489

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Published: Oct 01, 2024 | Modified: Oct 04, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
8.2 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Ubuntu

Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to missing check if the attribute resolves to the object prototype.

Weakness

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Affected Software

Name Vendor Start Version End Version
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support RedHat grafana-0:7.3.6-7.el8_4 *
Red Hat Enterprise Linux 8.4 Telecommunications Update Service RedHat grafana-0:7.3.6-7.el8_4 *
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions RedHat grafana-0:7.3.6-7.el8_4 *

Potential Mitigations

References