CVE-2021-23518
Summary
| CVE | CVE-2021-23518 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-21 20:15:00 UTC |
| Updated | 2023-02-03 19:16:00 UTC |
| Description | The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using the origin path as __proto__, the attribute of the object is accessed instead of a path. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-72573 |
Risk And Classification
Problem Types: CWE-1321
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cached-path-relative Project | Cached-path-relative | All | All | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Prototype Pollution in cached-path-relative | CVE-2021-23518 | Snyk | CONFIRM | snyk.io | |
| Prototype Pollution in org.webjars.npm:cached-path-relative | CVE-2021-23518 | Snyk | CONFIRM | snyk.io | |
| Fix other instances of prototype pollution vulnerability · ashaffer/cached-path-relative@40c73bf · GitHub | CONFIRM | github.com | |
| [SECURITY] [DLA 3221-1] node-cached-path-relative security update | MLIST | lists.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: P.Adithya Srinivas
LEGACY: Masudul Hasan Masud Bhuiyan
LEGACY: Cristian-Alexandru Staicu