GHSA-x3m3-4wpv-5vgc
HIGHCVE-2024-38999jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts..configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
- Affected
- <= 2.3.6
- Fixed in
- 2.3.7
- Weakness
- CWE-1321
- Published
- 2024-07-01
- Source
- github