CVE-2021-23450: Prototype Pollution
Published Dec 17, 2021
·Updated
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
Affected Software
11 affected components
linuxfoundation Dojo Node.js<1.17.0
Oracle Communications Policy Management=12.6.0.0.0
Oracle Primavera Unifier>=17.7<=17.12
Oracle Primavera Unifier=18.8
Oracle Primavera Unifier=19.12
Oracle Primavera Unifier=20.12
Oracle Primavera Unifier=21.12
Oracle WebLogic Server=12.2.1.4.0
Oracle WebLogic Server=14.1.1.0.0
Debian Debian Linux=10.0
IBM InfoSphere Data Architect<=9.2.1
Remediation
Patch Available
Patch Available
Event History
Dec 17, 2021
CVE Published
via MITRE·08:05 PM
Data Sourced
via MITRE·08:05 PM
DescriptionSeverityWeakness
Mar 4, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2021-23450?
CVE-2021-23450 is a vulnerability in Dojo that could allow a remote attacker to execute arbitrary code on the system.
2
How does CVE-2021-23450 affect IBM Security Verify Governance?
CVE-2021-23450 affects IBM Security Verify Governance version 10.0.
3
What is the severity of CVE-2021-23450?
CVE-2021-23450 has a severity rating of critical (9.8).
4
How can an attacker exploit CVE-2021-23450?
An attacker can exploit CVE-2021-23450 by sending a specially-crafted request to the system.
5
Are there any resources available for CVE-2021-23450?
Yes, you can find more information about CVE-2021-23450 at the following links: [Link 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/216463), [Link 2](https://www.ibm.com/support/pages/node/7047640).