CVE-2021-4278
A vulnerability classified as problematic has been found in cronvel tree-kit up to 0.6.x.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.43%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability classified as problematic has been found in cronvel tree-kit up to 0.6.x. This affects an unknown part. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). Upgrading to version 0.7.0 is able to address this issue. The name of the patch is a63f559c50d70e8cb2eaae670dec25d1dbc4afcd. It is recommended to upgrade the affected component. The identifier VDB-216765 was assigned to this vulnerability.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1321
- Affected
- tree kit project/tree kit
- Source
- cna@vuldb.com
References
- https://github.com/cronvel/tree-kit/commit/a63f559c50d70e8cb2eaae670dec25d1dbc4afcdPatch, Third Party Advisory
- https://github.com/cronvel/tree-kit/releases/tag/v0.7.0Release Notes, Third Party Advisory
- https://vuldb.com/?ctiid.216765Third Party Advisory
- https://vuldb.com/?id.216765Third Party Advisory
- https://github.com/cronvel/tree-kit/commit/a63f559c50d70e8cb2eaae670dec25d1dbc4afcdPatch, Third Party Advisory
- https://github.com/cronvel/tree-kit/releases/tag/v0.7.0Release Notes, Third Party Advisory
- https://vuldb.com/?ctiid.216765Third Party Advisory
- https://vuldb.com/?id.216765Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.