CVE-2024-57065
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Feb 5, 2025
Updated: Feb 6, 2025
CWE ID 1321
Summary
CVE-2024-57065 is a prototype pollution vulnerability affecting the lib.createPath function in utile v0.3.0. Attackers can exploit this issue by supplying a maliciously crafted payload, leading to a Denial of Service (DoS) condition. By manipulating the function's prototype object, attackers are able to inject unexpected data beyond the expected boundaries, causing unexpected behavior and potential crashes. This vulnerability poses a significant risk, as it can be used to disrupt the availability of applications using the affected library.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share