almela obx before v.0.0.4 has a Prototype Pollution issue which allows arbitrary code execution via the obx/build/index.js:656), reduce (@almela/obx/build/index.js:470), Object.set (obx/build/index.js:269) component.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-06-17T00:00:00

Updated: 2024-08-02T03:37:05.359Z

Reserved: 2024-05-30T00:00:00

Link: CVE-2024-36573

cve-icon Vulnrichment

Updated: 2024-07-19T19:27:48.319Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-17T16:15:14.947

Modified: 2024-11-21T09:22:25.083

Link: CVE-2024-36573

cve-icon Redhat

No data.