Bug 2311418 (CVE-2024-21529) - CVE-2024-21529 dset: Prototype Pollution
Summary: CVE-2024-21529 dset: Prototype Pollution
Keywords:
Status: NEW
Alias: CVE-2024-21529
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-09-11 05:20 UTC by OSIDB Bzimport
Modified: 2025-05-06 08:29 UTC (History)
23 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2024-09-11 05:20:33 UTC
Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user input sanitization. This vulnerability allows the attacker to inject malicious object property using the built-in Object property __proto__, which is recursively assigned to all the objects in the program.


Note You need to log in before you can comment on or make changes to this bug.