Prototype pollution in requirejs - CVE-2024-38999
Published: September 13, 2024 / Updated: February 18, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The vulnerability exists due to prototype pollution via the function s.contexts._.configure. A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in information disclosure or data manipulation.
Affected software
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Python 3 Module
openSUSE Leap
openEuler
Splunk DB Connect
Oracle Enterprise Data Quality
IBM Watson Discovery for IBM Cloud Pak for Data
Bitbucket Data Center
Moodle
Oracle Business Process Management Suite
Oracle Business Activity Monitoring
Oracle Business Intelligence Enterprise Edition
Cognos Dashboards on Cloud Pak for Data
Business Automation Insights
Planning Analytics Local
nodejs-requirejs
pgadmin4-web-uwsgi
pgadmin4
pgadmin4-cloud
pgadmin4-doc
system-user-pgadmin
pgadmin4-desktop
HPE Unified OSS Console (UOC)
Bitbucket Server
How to mitigate CVE-2024-38999
Splunk DB Connect - update to 4.0.0
Moodle - addressed in versions 4.1.16, 4.3.10, 4.4.6, 4.5.2
Planning Analytics Local - addressed in versions 2.0.0.99, 2.1.6
nodejs-requirejs - update to 2.1.11-3
HPE Unified OSS Console (UOC) - update to 3.1.8
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.6, 5.0.1
Cognos Dashboards on Cloud Pak for Data - update to 5.1
pgadmin4-web-uwsgi - update to 8.5-150600.3.6.1
pgadmin4 - update to 8.5-150600.3.6.1
pgadmin4-cloud - update to 8.5-150600.3.6.1
pgadmin4-doc - update to 8.5-150600.3.6.1
system-user-pgadmin - update to 8.5-150600.3.6.1
pgadmin4-desktop - update to 8.5-150600.3.6.1
Bitbucket Server - update to 8.19.25
Bitbucket Data Center - update to 8.19.25
Business Automation Insights - update to 24.0.0.0.1
External References
Related Security Bulletins
- Prototype pollution in jrburke requirejs
- Multiple vulnerabilities in IBM Watson Discovery
- Prototype pollution in Oracle Enterprise Data Quality
- Prototype pollution in Oracle Business Process Management Suite
- Prototype pollution in Oracle Business Activity Monitoring
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- Multiple vulnerabilities in IBM Business Automation Insights
- SUSE update for pgadmin4
- Multiple vulnerabilities in IBM Planning Analytics
- Multiple vulnerabilities in Moodle
- Multiple vulnerabilities in IBM Cognos Dashboards on Cloud Pak for Data
- Multiple vulnerabilities in HPE Unified OSS Console Assurance Monitoring (UOCAM)
- Splunk DB Connect update for third-party components
- Splunk DB Connect update for third-party components
- Bitbucket Data Center and Server update for requirejs
- openEuler update for nodejs-requirejs