In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Dell Powerstore Dsa2023366 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Oct 5, 2023 |
| Insert Special Characters Plugin | — | Update insert-special-characters plugin to version 1.0.5, or a newer patched version | May 15, 2025 | Apr 7, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 6, 2022 |
| Suse | — | Upgrade libbind9-1600Upgrade libdns1605Upgrade libisccfg1600Upgrade bind-docUpgrade libdns1605-32bitUpgrade libns1604Upgrade wireUpgrade libisc1606Upgrade grafanaUpgrade spacecmdUpgrade python3-bindUpgrade libisc1606-32bitUpgrade libbind9-1600-32bitUpgrade libirs1601Upgrade libirs1601-32bitUpgrade libisccc1600-32bitUpgrade bind-devel-32bitUpgrade bindUpgrade bind-utilsUpgrade libisccc1600Upgrade libns1604-32bitUpgrade golang-github-lusitaniae-apache_exporterUpgrade bind-chrootenvUpgrade bind-develUpgrade prometheus-postgres_exporterUpgrade libisccfg1600-32bitUpgrade dracut-saltbootUpgrade libirs-devel | Aug 9, 2024 | Apr 6, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub