CVE-2021-23438
Estado: ModificadaCrítica (9.8)—
This affects the package mpath before 0.8.4. A type confusion vulnerability can lead to a bypass of CVE-2018-16490. In particular, the condition ignoreProperties.indexOf(parts[i]) !== -1 returns -1 if parts[i] is ['__proto__']. This is because the method that has been called if the input is an array is Array.prototype.indexOf() and not String.prototype.indexOf(). They behave differently depending on the type of the input.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.72%
- Percentil entre todas las CVEs puntuadas: 77
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-843
Referencias
- https://github.com/aheckmann/mpath/commit/89402d2880d4ea3518480a8c9847c541f2d824fc
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1579548
- https://snyk.io/vuln/SNYK-JS-MPATH-1577289
- https://github.com/aheckmann/mpath/commit/89402d2880d4ea3518480a8c9847c541f2d824fc
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1579548
- https://snyk.io/vuln/SNYK-JS-MPATH-1577289
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-23438",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "report@snyk.io",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.6,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 3.4,
"exploitabilityScore": 2.2
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "report@snyk.io",
"affectedData": [
{
"vendor": "n/a",
"product": "mpath",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "0.8.4",
"versionType": "custom"
}
]
}
]
}
],
"published": "2021-09-01T19:15:07.440",
"references": [
{
"url": "https://github.com/aheckmann/mpath/commit/89402d2880d4ea3518480a8c9847c541f2d824fc",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1579548",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://snyk.io/vuln/SNYK-JS-MPATH-1577289",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://github.com/aheckmann/mpath/commit/89402d2880d4ea3518480a8c9847c541f2d824fc",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1579548",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://snyk.io/vuln/SNYK-JS-MPATH-1577289",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-843"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "This affects the package mpath before 0.8.4. A type confusion vulnerability can lead to a bypass of CVE-2018-16490. In particular, the condition ignoreProperties.indexOf(parts[i]) !== -1 returns -1 if parts[i] is ['__proto__']. This is because the method that has been called if the input is an array is Array.prototype.indexOf() and not String.prototype.indexOf(). They behave differently depending on the type of the input."
},
{
"lang": "es",
"value": "Esto afecta al paquete mpath versiones anteriores a 0.8.4. Una vulnerabilidad de confusión de tipo puede conllevar a una omisión de CVE-2018-16490. En concreto, la condición ignoreProperties.indexOf(parts[i]) !== -1 returns -1 if parts[i] is ['__proto__']. Esto es debido a que el método que se ha llamado si la entrada es un array es Array.prototype.indexOf() y no String.prototype.indexOf(). Se comportan de forma diferente según el tipo de entrada"
}
],
"lastModified": "2026-06-17T03:38:45.830",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mpath_project:mpath:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "511B6EA1-4264-40AE-95BF-1684AB5C2833",
"versionEndExcluding": "0.8.4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "report@snyk.io"
}