Vulnerabilities > CVE-2021-23449 - Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in VM2 Project VM2

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
vm2-project
CWE-915

Summary

This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitrary code on the host machine.