CRITICAL10.0
GHSA-x3m3-4wpv-5vgc
jrburke requirejs vulnerable to prototype pollution
Quick fix
GHSA-x3m3-4wpv-5vgc — requirejs: upgrade to the fixed version with the command below.
npm install requirejs@2.3.7Details
jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function `s.contexts._.configure`. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-38999[ADVISORY]
- https://github.com/requirejs/r.js/issues/1015[WEB]
- https://github.com/requirejs/requirejs/issues/1854[WEB]
- https://github.com/requirejs/requirejs/pull/1856/commits/ebd7a2ff71473542fa132d0d15c10fb4ed1539e1[WEB]
- https://gist.github.com/mestrtee/9acae342285bd2998fa09ebcb1e6d30a[WEB]
- https://github.com/requirejs/r.js[PACKAGE]
- https://security.snyk.io/vuln/SNYK-JS-REQUIREJS-5416713[WEB]