CVE-2021-41097
Summary
| CVE | CVE-2021-41097 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-27 18:15:00 UTC |
| Updated | 2022-09-30 02:31:00 UTC |
| Description | aurelia-path is part of the Aurelia platform and contains utilities for path manipulation. There is a prototype pollution vulnerability in aurelia-path before version 1.1.7. The vulnerability exposes Aurelia application that uses `aurelia-path` package to parse a string. The majority of this will be Aurelia applications that employ the `aurelia-router` package. An example is this could allow an attacker to change the prototype of base object class `Object` by tricking an application to parse the following URL: `https://aurelia.io/blog/?__proto__[asdf]=asdf`. The problem is patched in version `1.1.7`. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Release 1.1.7 · aurelia/path · GitHub |
MISC |
github.com |
|
| aurelia-path - npm |
MISC |
www.npmjs.com |
|
| Prototype Pollution · Issue #44 · aurelia/path · GitHub |
MISC |
github.com |
|
| Prototype pollution · Advisory · aurelia/path · GitHub |
CONFIRM |
github.com |
|
| fix: security issue gh closes #44 · aurelia/path@7c4e235 · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980493 Nodejs (npm) Security Update for aurelia-path (GHSA-3c9c-2p65-qvwv)