{"api_version":"1","generated_at":"2026-07-23T14:28:32+00:00","cve":"CVE-2021-23682","urls":{"html":"https://cve.report/CVE-2021-23682","api":"https://cve.report/api/cve/CVE-2021-23682.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-23682","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-23682"},"summary":{"title":"CVE-2021-23682","description":"This affects the package litespeed.js before 0.3.12; the package appwrite/server-ce from 0.12.0 and before 0.12.2, before 0.11.1. When parsing the query string in the getJsonFromUrl function, the key that is set in the result object is not properly sanitized leading to a Prototype Pollution vulnerability.","state":"PUBLIC","assigner":"report@snyk.io","published_at":"2022-02-16 17:15:00","updated_at":"2022-02-24 03:35:00"},"problem_types":["CWE-1321"],"metrics":[],"references":[{"url":"https://github.com/appwrite/appwrite/releases/tag/0.11.1","name":"N/A","refsource":"CONFIRM","tags":["Release Notes","Third Party Advisory"],"title":"Release Version 0.11.1 · appwrite/appwrite · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/appwrite/appwrite/releases/tag/0.12.2","name":"N/A","refsource":"CONFIRM","tags":["Release Notes","Third Party Advisory"],"title":"Release Version 0.12.2 · appwrite/appwrite · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://snyk.io/vuln/SNYK-JS-LITESPEEDJS-2359250","name":"N/A","refsource":"CONFIRM","tags":["Exploit","Third Party Advisory"],"title":"Prototype Pollution in litespeed.js | CVE-2021-23682 | Snyk","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/litespeed-js/litespeed.js/pull/18","name":"N/A","refsource":"CONFIRM","tags":["Patch","Third Party Advisory"],"title":"fix: prototype vulnerability in router by TorstenDittmann · Pull Request #18 · litespeed-js/litespeed.js · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/appwrite/appwrite/pull/2778","name":"N/A","refsource":"CONFIRM","tags":["Patch","Third Party Advisory"],"title":"fix: security patches for 0.12.2 by TorstenDittmann · Pull Request #2778 · appwrite/appwrite · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://snyk.io/vuln/SNYK-PHP-APPWRITESERVERCE-2401820","name":"N/A","refsource":"CONFIRM","tags":["Exploit","Third Party Advisory"],"title":"Prototype Pollution in appwrite/server-ce | CVE-2021-23682 | Snyk","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-23682","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-23682","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Alessio Della Libera of Snyk Research Team","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"23682","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"appwrite","cpe5":"appwrite","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"23682","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"litespeed.js_project","cpe5":"litespeed.js","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"node.js","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ASSIGNER":"report@snyk.io","DATE_PUBLIC":"2022-02-16T17:03:36.924290Z","ID":"CVE-2021-23682","STATE":"PUBLIC","TITLE":"Prototype Pollution"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"litespeed.js","version":{"version_data":[{"version_affected":"<","version_value":"0.3.12"}]}}]},"vendor_name":"n/a"},{"product":{"product_data":[{"product_name":"appwrite/server-ce","version":{"version_data":[{"version_affected":">=","version_value":"0.12.0"},{"version_affected":"<","version_value":"0.12.2"},{"version_affected":"<","version_value":"0.11.1"}]}}]},"vendor_name":"n/a"}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Prototype Pollution"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://snyk.io/vuln/SNYK-JS-LITESPEEDJS-2359250","name":"https://snyk.io/vuln/SNYK-JS-LITESPEEDJS-2359250"},{"refsource":"MISC","url":"https://snyk.io/vuln/SNYK-PHP-APPWRITESERVERCE-2401820","name":"https://snyk.io/vuln/SNYK-PHP-APPWRITESERVERCE-2401820"},{"refsource":"MISC","url":"https://github.com/litespeed-js/litespeed.js/pull/18","name":"https://github.com/litespeed-js/litespeed.js/pull/18"},{"refsource":"MISC","url":"https://github.com/appwrite/appwrite/releases/tag/0.12.2","name":"https://github.com/appwrite/appwrite/releases/tag/0.12.2"},{"refsource":"MISC","url":"https://github.com/appwrite/appwrite/pull/2778","name":"https://github.com/appwrite/appwrite/pull/2778"},{"refsource":"MISC","url":"https://github.com/appwrite/appwrite/releases/tag/0.11.1","name":"https://github.com/appwrite/appwrite/releases/tag/0.11.1"}]},"description":{"description_data":[{"lang":"eng","value":"This affects the package litespeed.js before 0.3.12; the package appwrite/server-ce from 0.12.0 and before 0.12.2, before 0.11.1. When parsing the query string in the getJsonFromUrl function, the key that is set in the result object is not properly sanitized leading to a Prototype Pollution vulnerability."}]},"impact":{"cvss":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"}},"credit":[{"lang":"eng","value":"Alessio Della Libera of Snyk Research Team"}]},"nvd":{"publishedDate":"2022-02-16 17:15:00","lastModifiedDate":"2022-02-24 03:35:00","problem_types":["CWE-1321"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:appwrite:appwrite:*:*:*:*:*:*:*:*","versionEndExcluding":"0.11.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:appwrite:appwrite:*:*:*:*:*:*:*:*","versionStartIncluding":"0.12.0","versionEndExcluding":"0.12.2","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:litespeed.js_project:litespeed.js:*:*:*:*:*:node.js:*:*","versionEndExcluding":"0.3.12","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"23682","Ordinal":"198409","Title":"CVE-2021-23682","CVE":"CVE-2021-23682","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"23682","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}