CVE-2024-21548

HIGH7.5EPSS 0.21%

Bun has an Application-level Prototype Pollution vulnerability in the runtime native API for Glo

發布日:2024/12/18修改日:2024/12/18

描述

Versions of the package bun before 1.1.30 are vulnerable to Prototype Pollution due to improper input sanitization. An attacker can exploit this vulnerability through Bun's APIs that accept objects.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

參考連結(5)