CVE-2021-43138
Summary
| CVE | CVE-2021-43138 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-06 17:15:00 UTC |
| Updated | 2023-11-07 03:39:00 UTC |
| Description | In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| async/mapValuesLimit.js at master · caolan/async · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 37 Update: yarnpkg-1.22.19-3.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| async/iterator.js at master · caolan/async · GitHub |
MISC |
github.com |
|
| Fix prototype pollution vulnerability · caolan/async@e1ecdbf · GitHub |
MISC |
github.com |
|
| async/CHANGELOG.md at v2.6.4 · caolan/async · GitHub |
MISC |
github.com |
Release Notes, Third Party Advisory |
| [SECURITY] Fedora 36 Update: yarnpkg-1.22.19-3.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Comparing v2.6.3...v2.6.4 · caolan/async · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 36 Update: yarnpkg-1.22.19-3.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: yarnpkg-1.22.19-3.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Edit fiddle - JSFiddle - Code Playground |
MISC |
jsfiddle.net |
|
| Fix prototype pollution vulnerability by mriedem · Pull Request #1828 · caolan/async · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 283621 Fedora Security Update for yarnpkg (FEDORA-2023-18fd476362)
- 283622 Fedora Security Update for yarnpkg (FEDORA-2023-ce8943223c)
- 379452 IBM Cognos Analytics Multiple Vulnerabilities (7123154)
- 754116 SUSE Enterprise Linux Security Update for SUSE Manager Client Tools (SUSE-SU-2023:2578-1)
- 755764 SUSE Enterprise Linux Security Update for SUSE Manager Client Tools (SUSE-SU-2024:0487-1)