Rewterz
Rewterz Threat Advisory – CVE-2021-1284 – Cisco SD-WAN vManage Software Authentication Bypass Vulnerability
May 6, 2021
Rewterz
Rewterz Threat Alert – 10 APT Groups Exploit Microsoft Exchange Security Flaws
May 12, 2021

Rewterz Threat Advisory – CVE-2021-29491 – Node.js Mixme Module Vulnerability

Severity

High

Analysis Summary

CVE-2021-29491

Node.js mixme module is vulnerable to a denial of service which is caused by a prototype pollution flaw in the mutate() and merge() functions. A remote attacker can exploit the vulnerability by sending a specially-crafted request that can cause a denial of service condition.

Impact

Denial of Service

Affected Vendors

Node.js

Affected Products

Node.js mixme 0.5.0

Remediation

Upgrade to the latest version of mixme (0.5.1 or later) at https://www.npmjs.com/advisories/1668