CVE-2021-3918

json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Prototype Pollution
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
Affected Products (NVD)
VendorProductVersion
json-schema_projectjson-schema
𝑥
< 0.4.0
debiandebian_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
node-json-schema
bookworm
0.4.0+~7.0.11-1
fixed
bullseye
0.3.0+~7.0.6-1+deb11u1
fixed
sid
0.4.0+~7.0.11-1
fixed
trixie
0.4.0+~7.0.11-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-json-schema
bionic
Fixed 0.2.3-1+deb10u1build0.18.04.1
released
focal
Fixed 0.2.3-1+deb10u1build0.20.04.1
released
hirsute
ignored
impish
ignored
jammy
not-affected
kinetic
not-affected
lunar
not-affected
trusty
ignored
xenial
ignored
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
bind
suse enterprise server 15 SP1
9.16.6-150000.12.65.1
fixed
suse enterprise server 15 SP2
9.16.6-150000.12.65.1
fixed
bind-chrootenv
suse enterprise server 15 SP1
9.16.6-150000.12.65.1
fixed
suse enterprise server 15 SP2
9.16.6-150000.12.65.1
fixed
bind-devel
suse enterprise server 15 SP1
9.16.6-150000.12.65.1
fixed
suse enterprise server 15 SP2
9.16.6-150000.12.65.1
fixed
bind-doc
suse enterprise server 15 SP1
9.16.6-150000.12.65.1
fixed
suse enterprise server 15 SP2
9.16.6-150000.12.65.1
fixed
bind-utils
suse enterprise server 15 SP1
9.16.6-150000.12.65.1
fixed
suse enterprise server 15 SP2
9.16.6-150000.12.65.1
fixed
libbind9-1600
suse enterprise server 15 SP1
9.16.6-150000.12.65.1
fixed
suse enterprise server 15 SP2
9.16.6-150000.12.65.1
fixed
libdns1605
suse enterprise server 15 SP1
9.16.6-150000.12.65.1
fixed
suse enterprise server 15 SP2
9.16.6-150000.12.65.1
fixed
libirs-devel
suse enterprise server 15 SP1
9.16.6-150000.12.65.1
fixed
suse enterprise server 15 SP2
9.16.6-150000.12.65.1
fixed
libirs1601
suse enterprise server 15 SP1
9.16.6-150000.12.65.1
fixed
suse enterprise server 15 SP2
9.16.6-150000.12.65.1
fixed
libisc1606
suse enterprise server 15 SP1
9.16.6-150000.12.65.1
fixed
suse enterprise server 15 SP2
9.16.6-150000.12.65.1
fixed
libisccc1600
suse enterprise server 15 SP1
9.16.6-150000.12.65.1
fixed
suse enterprise server 15 SP2
9.16.6-150000.12.65.1
fixed
libisccfg1600
suse enterprise server 15 SP1
9.16.6-150000.12.65.1
fixed
suse enterprise server 15 SP2
9.16.6-150000.12.65.1
fixed
libns1604
suse enterprise server 15 SP1
9.16.6-150000.12.65.1
fixed
suse enterprise server 15 SP2
9.16.6-150000.12.65.1
fixed
nodejs-common
suse enterprise server 15
2.0-3.4.1
fixed
suse enterprise server 15 SP1
2.0-3.4.1
fixed
suse enterprise server 15 SP2
2.0-3.4.1
fixed
nodejs10
suse enterprise server 15
10.24.1-150000.1.44.1
fixed
suse enterprise server 15 SP1
10.24.1-150000.1.44.1
fixed
suse enterprise server 15 SP2
10.24.1-150000.1.44.1
fixed
nodejs10-devel
suse enterprise server 15
10.24.1-150000.1.44.1
fixed
suse enterprise server 15 SP1
10.24.1-150000.1.44.1
fixed
suse enterprise server 15 SP2
10.24.1-150000.1.44.1
fixed
nodejs10-docs
suse enterprise server 15
10.24.1-150000.1.44.1
fixed
suse enterprise server 15 SP1
10.24.1-150000.1.44.1
fixed
suse enterprise server 15 SP2
10.24.1-150000.1.44.1
fixed
nodejs12
suse enterprise sap 15 SP3
12.22.10-4.29.3
fixed
suse enterprise server 15 SP2
12.22.10-4.29.3
fixed
suse enterprise server 15 SP3
12.22.10-4.29.3
fixed
nodejs12-devel
suse enterprise sap 15 SP3
12.22.10-4.29.3
fixed
suse enterprise server 15 SP2
12.22.10-4.29.3
fixed
suse enterprise server 15 SP3
12.22.10-4.29.3
fixed
nodejs12-docs
suse enterprise sap 15 SP3
12.22.10-4.29.3
fixed
suse enterprise server 15 SP2
12.22.10-4.29.3
fixed
suse enterprise server 15 SP3
12.22.10-4.29.3
fixed
nodejs14
suse enterprise sap 15 SP3
14.19.0-15.27.1
fixed
suse enterprise server 15 SP2
14.19.0-15.27.1
fixed
suse enterprise server 15 SP3
14.19.0-15.27.1
fixed
nodejs14-devel
suse enterprise sap 15 SP3
14.19.0-15.27.1
fixed
suse enterprise server 15 SP2
14.19.0-15.27.1
fixed
suse enterprise server 15 SP3
14.19.0-15.27.1
fixed
nodejs14-docs
suse enterprise sap 15 SP3
14.19.0-15.27.1
fixed
suse enterprise server 15 SP2
14.19.0-15.27.1
fixed
suse enterprise server 15 SP3
14.19.0-15.27.1
fixed
nodejs8
suse enterprise server 15
8.17.0-3.54.2
fixed
suse enterprise server 15 SP1
8.17.0-3.54.2
fixed
suse enterprise server 15 SP2
8.17.0-10.19.2
fixed
nodejs8-devel
suse enterprise server 15
8.17.0-3.54.2
fixed
suse enterprise server 15 SP1
8.17.0-3.54.2
fixed
suse enterprise server 15 SP2
8.17.0-10.19.2
fixed
nodejs8-docs
suse enterprise server 15
8.17.0-3.54.2
fixed
suse enterprise server 15 SP1
8.17.0-3.54.2
fixed
suse enterprise server 15 SP2
8.17.0-10.19.2
fixed
npm10
suse enterprise server 15
10.24.1-150000.1.44.1
fixed
suse enterprise server 15 SP1
10.24.1-150000.1.44.1
fixed
suse enterprise server 15 SP2
10.24.1-150000.1.44.1
fixed
npm12
suse enterprise sap 15 SP3
12.22.10-4.29.3
fixed
suse enterprise server 15 SP2
12.22.10-4.29.3
fixed
suse enterprise server 15 SP3
12.22.10-4.29.3
fixed
npm14
suse enterprise sap 15 SP3
14.19.0-15.27.1
fixed
suse enterprise server 15 SP2
14.19.0-15.27.1
fixed
suse enterprise server 15 SP3
14.19.0-15.27.1
fixed
npm8
suse enterprise server 15
8.17.0-3.54.2
fixed
suse enterprise server 15 SP1
8.17.0-3.54.2
fixed
suse enterprise server 15 SP2
8.17.0-10.19.2
fixed
python3-bind
suse enterprise server 15 SP1
9.16.6-150000.12.65.1
fixed
suse enterprise server 15 SP2
9.16.6-150000.12.65.1
fixed