Description
The package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in src/SearchParameters/index.jsSearchParameters._parseNumbers without any protection against prototype properties. Note that this vulnerability is only exploitable if the implementation allows users to define arbitrary search patterns.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2399 | The package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in src/SearchParameters/index.jsSearchParameters._parseNumbers without any protection against prototype properties. Note that this vulnerability is only exploitable if the implementation allows users to define arbitrary search patterns. |
Github GHSA |
GHSA-vpf5-82c8-9v36 | Prototype Pollution in algoliasearch-helper |
References
History
No history.
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-09-16T19:45:53.608Z
Reserved: 2021-01-08T00:00:00.000Z
Link: CVE-2021-23433
No data.
Status : Modified
Published: 2021-11-19T20:15:17.903
Modified: 2024-11-21T05:51:45.037
Link: CVE-2021-23433
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA