CVE-2021-42581

NameCVE-2021-42581
DescriptionPrototype poisoning in function mapObjIndexed in Ramda 0.27.0 and earlier allows attackers to compromise integrity or availability of application via supplying a crafted object (that contains an own property "__proto__") as an argument to the function. NOTE: the vendor disputes this because the observed behavior only means that a user can create objects that the user didn't know would contain custom prototypes
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Notes

Disputed issue against Node ramda
https://github.com/ramda/ramda/pull/3192
https://jsfiddle.net/3pomzw5g/2/
http://link.fourwindssoft.com/52
http://link.fourwindssoft.com/53

Search for package or bug name: Reporting problems