Versions of the package web3-utils before 4.2.1 are vulnerable to Prototype Pollution via the utility functions format and mergeDeep, due to insecure recursive merge. An attacker can manipulate an object's prototype, potentially leading to the alteration of the behavior of all objects inheriting from the affected prototype by passing specially crafted input to these functions.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published: 2024-03-25T05:00:00.749Z

Updated: 2024-08-23T19:10:40.905Z

Reserved: 2023-12-22T12:33:20.119Z

Link: CVE-2024-21505

cve-icon Vulnrichment

Updated: 2024-08-01T22:20:40.897Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-25T05:15:50.663

Modified: 2024-08-01T18:35:20.240

Link: CVE-2024-21505

cve-icon Redhat

No data.