CVE-2021-23440: Prototype Pollution
A type confusion vulnerability can lead to a bypass of CVE-2019-10747 when the user-provided keys used in the path parameter are arrays.
External Reference:
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1584212
Other sources
Nodejs set-value module could allow a remote attacker to execute arbitrary code on the system, caused by a prototype pollution flaw. By adding or modifying properties of Object.prototype using a proto or constructor payload, an attacker could exploit this vulnerability to execute arbitrary code on the system.
— IBM
This affects the package set-value. A type confusion vulnerability can lead to a bypass of CVE-2019-10747 when the user-provided keys used in the path parameter are arrays.
This affects the package set-value before <2.0.1, >=3.0.0 <4.0.1. A type confusion vulnerability can lead to a bypass of CVE-2019-10747 when the user-provided keys used in the path parameter are arrays.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-23440?
CVE-2021-23440 is a type confusion vulnerability in the set-value package before version 2.0.1 and between version 3.0.0 and 4.0.1.
How does CVE-2021-23440 affect the set-value package?
CVE-2021-23440 can lead to a bypass of CVE-2019-10747 when the user-provided keys used in the path parameter are arrays.
What is the severity of CVE-2021-23440?
CVE-2021-23440 has a severity rating of 9.8, which is considered critical.
Which software is affected by CVE-2021-23440?
The set-value package versions before 2.0.1 and between 3.0.0 and 4.0.1 are affected by CVE-2021-23440, as well as Oracle Communications Cloud Native Core Policy version 1.14.0.
How can I fix CVE-2021-23440?
To fix CVE-2021-23440, update the set-value package to version 4.0.1 or apply the necessary security patches provided by the software vendor.