Back

CRITICAL

Prototype Pollution in immerjs/immer

Published Sep 2, 2021

Description

immer is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Affected products

Remediation

Red Hat statement

In OpenShift Container Platform (OCP) and OpenShift Migration Toolkit for Containers (MTC), the affected components are behind OpenShift OAuth authentication. This restricts access to the vulnerable nodejs-immer library to authenticated users only, therefore the impact is Low.

Weaknesses (2)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntrdev
Published Sep 2, 2021
Updated Aug 3, 2024
Reserved Aug 31, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Aug 30, 2021
ENISA EUVD
Assigner @huntrdev
Published Sep 2, 2021
Updated Aug 3, 2024
Exploited since n/a
EUVD-2021-2031 GHSA-C36V-FMGQ-M8HX