CVE-2021-44906
minimist: prototype pollution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
5Exploited in Wild
-Decision
Descriptions
Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
Minimist versiones anteriores a 1.2.5 incluyéndola, es vulnerable a una Contaminación de Prototipos por medio del archivo index.js, función setKey() (líneas 69-95)
An Uncontrolled Resource Consumption flaw was found in minimist. This flaw allows an attacker to trick the library into adding or modifying the properties of Object.prototype, using a constructor or __proto__ payload, resulting in prototype pollution and loss of confidentiality, availability, and integrity.
Red Hat Single Sign-On 7.6 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications. This release of Red Hat Single Sign-On 7.6.2 serves as a replacement for Red Hat Single Sign-On 7.6.1, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Issues addressed include code execution, cross site scripting, denial of service, deserialization, html injection, memory exhaustion, open redirection, server-side request forgery, and traversal vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-12-13 CVE Reserved
- 2022-03-17 CVE Published
- 2023-10-02 First Exploit
- 2024-08-04 CVE Updated
- 2025-04-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
https://security.netapp.com/advisory/ntap-20240621-0006 |
|
|
https://stackoverflow.com/questions/8588563/adding-custom-properties-to-a-function/20278068#20278068 | Issue Tracking |
URL | Date | SRC |
---|---|---|
https://github.com/nevermoe/CVE-2021-44906 | 2023-10-02 | |
https://github.com/Marynk/JavaScript-vulnerability-detection/blob/main/minimist%20PoC.zip | 2024-08-04 | |
https://github.com/substack/minimist/blob/master/index.js#L69 | 2024-08-04 | |
https://github.com/substack/minimist/issues/164 | 2024-08-04 | |
https://snyk.io/vuln/SNYK-JS-MINIMIST-559764 | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2021-44906 | 2025-02-24 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2066009 | 2025-02-24 |