
Cloud Vulnerability DB
A community-led vulnerabilities database
All versions of package lutils are vulnerable to Prototype Pollution via the main (merge) function. The vulnerability was assigned CVE-2021-23396 and was disclosed on June 17, 2021. This security issue affects all versions of the lutils package running on Node.js (NVD).
The vulnerability is classified as Prototype Pollution (CWE-1321), which involves improperly controlled modification of object prototype attributes. The CVSS v3.1 base scores vary between sources, with NVD assigning a Critical score of 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) while Snyk rates it as Medium with a score of 5.6 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L) (NVD).
The vulnerability allows an attacker to modify properties within the global prototype chain through the main (merge) function. This can lead to denial of service (DoS) at minimum, and potentially allow for more severe impacts including property manipulation across the application (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."