CVE Vulnerabilities

CVE-2024-38999

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Published: Jul 01, 2024 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

Weakness

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Affected Software

NameVendorStart VersionEnd Version
RequirejsUbuntufocal*
RequirejsUbuntumantic*
RequirejsUbuntuoracular*
RequirejsUbuntuplucky*

Potential Mitigations

References