CVE-2024-21529 - Apache dset Prototype Pollution Vulnerability

1 month ago 27
ARTICLE AD BOX
CVE ID : CVE-2024-21529
Published : Sept. 11, 2024, 5:15 a.m. | 24 minutes ago
Description : Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user input sanitization. This vulnerability allows the attacker to inject malicious object property using the built-in Object property __proto__, which is recursively assigned to all the objects in the program.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article