CVE-2024-21548
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
18/12/2024
Last modified:
18/12/2024
Description
Versions of the package bun before 1.1.30 are vulnerable to Prototype Pollution due to improper input sanitization. An attacker can exploit this vulnerability through Bun's APIs that accept objects.
Impact
Base Score 4.0
7.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH