CVE-2021-4264: LinkedIn dustjs prototype pollution
A vulnerability was found in LinkedIn dustjs up to 2.x and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.0.0 is able to address this issue. The name of the patch is ddb6523832465d38c9d80189e9de60519ac307c3. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216464.
Other sources
LinkedIn Dust.js could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a prototype pollution flaw. By adding or modifying properties of Object.prototype using a proto or constructor payload, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-4264.
What is the severity of CVE-2021-4264?
The severity of CVE-2021-4264 is high.
What is the affected software of CVE-2021-4264?
The affected software of CVE-2021-4264 is LinkedIn dustjs up to version 2.x.
What is the type of vulnerability in CVE-2021-4264?
The type of vulnerability in CVE-2021-4264 is prototype pollution.
How can I fix CVE-2021-4264?
To fix CVE-2021-4264, it is recommended to update to a version higher than 3.0.0 of LinkedIn dustjs.