CVE-2024-57708
OneTrust SDK 6.33.0 - Denial Of Service (DoS)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __proto__, and Object.assign components
An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __proto__, and Object.assign components. NOTE: this is disputed by the Supplier who does not agree it is a prototype pollution vulnerability.
A vulnerability exists in OneTrust SDK version 6.33.0 that allows an attacker to perform prototype pollution via the misuse of Object.setPrototypeOf and Object.assign. An attacker can inject malicious properties into the prototype chain, potentially causing a denial of service or altering the behavior of inherited objects throughout the application.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2025-01-09 CVE Reserved
- 2025-06-23 CVE Published
- 2025-06-23 First Exploit
- 2025-06-26 CVE Updated
- 2025-07-01 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-400: Uncontrolled Resource Consumption
- CWE-471: Modification of Assumed-Immutable Data (MAID)
- CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes
- CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://discord.com/assets/oneTrust/v4/scripttemplates/6.33.0/otBannerSdk.js | ||
https://github.com/brotheralameen1/Discordforschool/security/advisories/GHSA-63xr-98vc-whx5 |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/201222 | 2025-06-23 | |
https://www.exploit-db.com/exploits/52340 | 2025-06-26 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
- | - | - | - | - |