Prototype pollution in vm2 - CVE-2021-23449
Published: December 30, 2022
Vulnerability identifier: #VU70542
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-23449
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can perform prototype pollution attack and execute arbitrary code on the server.
Affected software
vm2
IBM Cloud Automation Manager
Cloud Pak for Multicloud Management Infrastructure Management
IBM Cloud Automation Manager
Cloud Pak for Multicloud Management Infrastructure Management
How to mitigate CVE-2021-23449
Install update from vendor's website.
vm2 - update to 3.9.4
Cloud Pak for Multicloud Management Infrastructure Management - update to 2.3 Fix Pack 5
Cloud Pak for Multicloud Management Infrastructure Management - update to 2.3 Fix Pack 5