← All CVEs

CVE-2021-23450

high · 7.5

All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.

7.5
CVSS
30.4%
EPSS (exploit prob.)
98th
EPSS percentile
2021-12-17
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-1321

Affected products

VendorProductAffected versions
linuxfoundationdojo< 1.17.0
oraclecommunications_policy_management12.6.0.0.0
oracleprimavera_unifier>= 17.7, <= 17.12
oracleprimavera_unifier18.8
oracleprimavera_unifier19.12
oracleprimavera_unifier20.12
oracleprimavera_unifier21.12
oracleweblogic_server12.2.1.4.0
oracleweblogic_server14.1.1.0.0
debiandebian_linux10.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-23450