Junglewise Threat Intelligence

CVE-2021-29491: Prototype Pollution in mixme

CVE-2021-29491 · Severity: low · CVSS 3.1 · Published 2022-02-10

Vendors: npm.

Executive brief

mixme is a Node.js library that provides object manipulation utilities. Versions before 0.5.1 are vulnerable to prototype pollution attacks where an attacker can inject malicious properties via the merge() and mutate() functions. This can cause application-wide denial of service by corrupting shared object prototypes.

Technical details

The vulnerability is a prototype pollution flaw (CWE-913/CWE-676) in the mixme library's merge() and mutate() functions. An attacker can exploit the lack of property name filtering to inject or modify the '__proto__' property, causing arbitrary properties to be added to all objects in the application. This requires the attacker to have the ability to call these functions with untrusted input (e.g., via an API endpoint that accepts user-controlled objects). The pollution results in denial of service by breaking object functionality. The issue was patched in version 0.5.1.

Affected products

  • Adaltas mixme before 0.5.1

CVE identifiers

  • CVE-2021-29491
  • CVE-2021-28860

Timeline

  • 2021-05-05: disclosed: Vulnerability published
  • 2021-05-06: patched: Version 0.5.1 released with fix

References

Related threats