CVE-2024-57084

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Feb 5, 2025
Updated: Feb 7, 2025
CWE ID 1321

Summary

CVE-2024-57084 is a prototype pollution vulnerability affecting the lib.parse function in the dot-properties library version 1.0.1. This issue permits attackers to supply a crafted payload that causes a Denial of Service (DoS) by corrupting the prototype chain. This vulnerability may result in unintended function calls or memory exhaustion, leading to a service outage. It is highly recommended that users upgrade to a patched version of dot-properties to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share