CRITICAL 10.0 npm
jrburke requirejs vulnerable to prototype pollution
GHSA-x3m3-4wpv-5vgc · CVE-2024-38999
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2024-38999
- WEB https://github.com/requirejs/r.js/issues/1015
- WEB https://github.com/requirejs/requirejs/issues/1854
- WEB https://github.com/requirejs/requirejs/pull/1856/commits/ebd7a2ff71473542fa132d0d15c10fb4ed1539e1
- WEB https://gist.github.com/mestrtee/9acae342285bd2998fa09ebcb1e6d30a
- PACKAGE https://github.com/requirejs/r.js
- WEB https://security.snyk.io/vuln/SNYK-JS-REQUIREJS-5416713
Ready to move
Start Securing
Free, no credit card | First findings in minutes