Prototype pollution in vm2 - CVE-2021-23449

 

Prototype pollution in vm2 - CVE-2021-23449

Published: December 30, 2022


Vulnerability identifier: #VU70542
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-23449
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary JavaScript code.

The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can perform prototype pollution attack and execute arbitrary code on the server.



Affected software

vm2
IBM Cloud Automation Manager
Cloud Pak for Multicloud Management Infrastructure Management

How to mitigate CVE-2021-23449

Install update from vendor's website.

vm2 - update to 3.9.4
Cloud Pak for Multicloud Management Infrastructure Management - update to 2.3 Fix Pack 5

External References

Related Security Bulletins