Versions of the package web3-utils before 4.2.1 are vulnerable to Prototype Pollution via the utility functions format and mergeDeep, due to insecure recursive merge.
An attacker can manipulate an object's prototype, potentially leading to the alteration of the behavior of all objects inheriting from the affected prototype by passing specially crafted input to these functions.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: snyk
Published: 2024-03-25T05:00:00.749Z
Updated: 2024-08-23T19:10:40.905Z
Reserved: 2023-12-22T12:33:20.119Z
Link: CVE-2024-21505
Vulnrichment
Updated: 2024-08-01T22:20:40.897Z
NVD
Status : Awaiting Analysis
Published: 2024-03-25T05:15:50.663
Modified: 2024-08-01T18:35:20.240
Link: CVE-2024-21505
Redhat
No data.