CVE-2024-57074
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-57074 is a prototype pollution vulnerability affecting the lib.merge function in xe-utils version 3.5.31. Maliciously crafted input can cause a Denial of Service (DoS) by corrupting the prototype chain in this function. Attackers can exploit this flaw to disrupt the normal functioning of the application, potentially causing significant inconvenience or downtime. The impact of this vulnerability is limited to DoS, but it serves as an important reminder for developers to implement proper input validation and sanitization techniques to prevent such attacks. It's recommended that users of xe-utils 3.5.31 update to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.