
Cloud Vulnerability DB
A community-led vulnerabilities database
utils.js was found to be vulnerable to Improperly Controlled Modification of Object Prototype Attributes, also known as Prototype Pollution. The vulnerability was assigned CVE-2021-3815 and was discovered in September 2021 (CVE Mitre).
The vulnerability exists in the ObjectUtil.js component of the utils.js library where object prototype attributes could be modified improperly. The issue specifically involved the ability to manipulate the 'proto' property, which could lead to prototype pollution attacks (Github Commit).
The vulnerability could allow an attacker to modify the prototype of JavaScript objects, potentially affecting all objects in the application and leading to security issues across the application (CVE Mitre).
The issue was fixed by adding a check for the 'proto' key in the object manipulation logic, preventing prototype pollution attempts. The fix was implemented in a commit that added specific protection against prototype pollution (Github Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."