VDB
Sign up
CRITICAL10.0

GHSA-x3m3-4wpv-5vgc

jrburke requirejs vulnerable to prototype pollution

Quick fix

GHSA-x3m3-4wpv-5vgc — requirejs: upgrade to the fixed version with the command below.

npm install requirejs@2.3.7

Details

jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function `s.contexts._.configure`. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/requirejs
Introduced in: 0Fixed in: 2.3.7
Fixnpm install requirejs@2.3.7

References