CVE-2021-23771 Information
Jun 07, 2022
cve
Description
This affects all versions of package notevil; all versions of package argencoders-notevil. It is vulnerable to Sandbox Escape leading to Prototype pollution. The package fails to restrict access to the main context allowing an attacker to add or modify an object’s prototype. Note: This vulnerability derives from an incomplete fix in SNYK-JS-NOTEVIL-608878.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Reference
https://snyk.io/vuln/SNYK-JS-NOTEVIL-2385946 https://snyk.io/vuln/SNYK-JS-ARGENCODERSNOTEVIL-2388587
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.5
Share on: