CVE-2024-38999
jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function `s.contexts._.configure`. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
05 / REFERENCES
Further evidence
- https://gist.github.com/mestrtee/9acae342285bd2998fa09ebcb1e6d30a
- https://github.com/requirejs/r.js
- https://github.com/requirejs/r.js/issues/1015
- https://github.com/requirejs/requirejs/issues/1854
- https://github.com/requirejs/requirejs/pull/1856/commits/ebd7a2ff71473542fa132d0d15c10fb4ed1539e1
- https://nvd.nist.gov/vuln/detail/CVE-2024-38999
- https://security.snyk.io/vuln/SNYK-JS-REQUIREJS-5416713