CVE-2021-25945

Related Vulnerabilities: CVE-2021-25945  

A flaw has been identified in nodejs-extend. A prototype pollution vulnerability allows attackers to cause a denial of service and may lead to remote code execution. The highest threat from this vulnerability is to system availability.

Description

A flaw has been identified in nodejs-extend. A prototype pollution vulnerability allows attackers to cause a denial of service and may lead to remote code execution. The highest threat from this vulnerability is to system availability.

Additional Information

  • Bugzilla 1965478: CVE-2021-25945 nodejs-extend: prototype pollution allows attacker to cause a denial of service and may lead to remote code execution
  • CWE-94: Improper Control of Generation of Code ('Code Injection')
  • FAQ: Frequently asked questions about CVE-2021-25945