FlawAtlas
Search the atlas
CVE-2024-38999 High

CVE-2024-38999

jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

Exploit probability 0.8%
Published July 1, 2024
Required by Not available
Last source change April 10, 2026

02 / AFFECTED SOFTWARE

Affected packages

npm requirejs

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2024-38999

jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

View original source
Open Source Vulnerabilities GHSA-x3m3-4wpv-5vgc

jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function `s.contexts._.configure`. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

View original source

05 / REFERENCES

Further evidence