CVE-2024-52810
Last modified
CVE-2024-52810 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. @intlify/shared is a shared library for the intlify project. The latest version of @intlify/shared (10.0.4) is vulnerable to Prototype Pollution through the entry function(s) lib.deepCopy. EPSS estimates a 0.73% chance of exploitation in the next 30 days.
Description
@intlify/shared is a shared library for the intlify project. The latest version of @intlify/shared (10.0.4) is vulnerable to Prototype Pollution through the entry function(s) lib.deepCopy. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the global prototype chain, causing denial of service (DoS) as the minimum consequence. Moreover, the consequences of this vulnerability can escalate to other injection-based attacks, depending on how the library integrates within the application. For instance, if the polluted property propagates to sensitive Node.js APIs (e.g., exec, eval), it could enable an attacker to execute arbitrary commands within the application's context. This issue has been addressed in versions 9.14.2, and 10.0.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-52810?
How severe is CVE-2024-52810?
How do I fix CVE-2024-52810?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-52804Tornado is a Python web framework and asynchronous networkin…7.5
- CVE-2024-52805Synapse is an open-source Matrix homeserver. In Synapse befo…7.5
- CVE-2024-52806SimpleSAMLphp SAML2 library is a PHP library for SAML2 relat…8.3
- CVE-2024-52807The HL7 FHIR IG publisher is a tool to take a set of inputs …8.6
- CVE-2024-52809vue-i18n is an internationalization plugin for Vue.js. In a…5.3
- CVE-2024-5281The wp-affiliate-platform WordPress plugin before 6.5.1 does…6.1
- CVE-2024-52811The ngtcp2 project is an effort to implement IETF QUIC proto…8.2
- CVE-2024-52812LF Edge eKuiper is an internet-of-things data analytics and …5.4
- CVE-2024-52813matrix-rust-sdk is an implementation of a Matrix client-serv…4.3
- CVE-2024-52814Argo Helm is a collection of community maintained charts for…2.8
- CVE-2024-52815Synapse is an open-source Matrix homeserver. Synapse version…5.3
- CVE-2024-52816Adobe Experience Manager versions 6.5.21 and earlier are aff…5.4
Are you affected by CVE-2024-52810?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
