CVE-2021-23771 Information

Description

This affects all versions of package notevil; all versions of package argencoders-notevil. It is vulnerable to Sandbox Escape leading to Prototype pollution. The package fails to restrict access to the main context allowing an attacker to add or modify an object’s prototype. Note: This vulnerability derives from an incomplete fix in SNYK-JS-NOTEVIL-608878.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Reference

https://snyk.io/vuln/SNYK-JS-NOTEVIL-2385946 https://snyk.io/vuln/SNYK-JS-ARGENCODERSNOTEVIL-2388587

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

6.5

Share on: