CVE-2021-23682
Summary
| CVE | CVE-2021-23682 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-16 17:15:00 UTC |
| Updated | 2022-02-24 03:35:00 UTC |
| Description | This affects the package litespeed.js before 0.3.12; the package appwrite/server-ce from 0.12.0 and before 0.12.2, before 0.11.1. When parsing the query string in the getJsonFromUrl function, the key that is set in the result object is not properly sanitized leading to a Prototype Pollution vulnerability. |
Risk And Classification
Problem Types: CWE-1321
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Appwrite | Appwrite | All | All | All | All |
| Application | Litespeed.js Project | Litespeed.js | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release Version 0.11.1 · appwrite/appwrite · GitHub | CONFIRM | github.com | Release Notes, Third Party Advisory |
| Release Version 0.12.2 · appwrite/appwrite · GitHub | CONFIRM | github.com | Release Notes, Third Party Advisory |
| Prototype Pollution in litespeed.js | CVE-2021-23682 | Snyk | CONFIRM | snyk.io | Exploit, Third Party Advisory |
| fix: prototype vulnerability in router by TorstenDittmann · Pull Request #18 · litespeed-js/litespeed.js · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| fix: security patches for 0.12.2 by TorstenDittmann · Pull Request #2778 · appwrite/appwrite · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| Prototype Pollution in appwrite/server-ce | CVE-2021-23682 | Snyk | CONFIRM | snyk.io | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Alessio Della Libera of Snyk Research Team
There are currently no legacy QID mappings associated with this CVE.