{
   "CVE_data_meta":{
      "ASSIGNER":"security@huntr.dev",
      "ID":"CVE-2021-3766",
      "STATE":"PUBLIC",
      "TITLE":"Prototype Pollution in vincit/objection.js"
   },
   "affects":{
      "vendor":{
         "vendor_data":[
            {
               "product":{
                  "product_data":[
                     {
                        "product_name":"vincit/objection.js",
                        "version":{
                           "version_data":[
                              {
                                 "version_affected":"<",
                                 "version_value":"2.2.16"
                              }
                           ]
                        }
                     }
                  ]
               },
               "vendor_name":"vincit"
            }
         ]
      }
   },
   "data_format":"MITRE",
   "data_type":"CVE",
   "data_version":"4.0",
   "description":{
      "description_data":[
         {
            "lang":"eng",
            "value":"objection.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')"
         }
      ]
   },
   "impact":{
      "cvss":{
         "attackComplexity":"LOW",
         "attackVector":"NETWORK",
         "availabilityImpact":"HIGH",
         "baseScore":7.5,
         "baseSeverity":"HIGH",
         "confidentialityImpact":"NONE",
         "integrityImpact":"NONE",
         "privilegesRequired":"NONE",
         "scope":"UNCHANGED",
         "userInteraction":"NONE",
         "vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
         "version":"3.0"
      }
   },
   "problemtype":{
      "problemtype_data":[
         {
            "description":[
               {
                  "lang":"eng",
                  "value":"CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')"
               }
            ]
         }
      ]
   },
   "references":{
      "reference_data":[
         {
            "name":"https://huntr.dev/bounties/c98e0f0e-ebf2-4072-be73-a1848ea031cc",
            "refsource":"CONFIRM",
            "url":"https://huntr.dev/bounties/c98e0f0e-ebf2-4072-be73-a1848ea031cc"
         },
         {
            "name":"https://github.com/Vincit/objection.js/commit/46b842a6bc897198b83f41ac85c92864b991d7e9",
            "refsource":"MISC",
            "url":"https://github.com/Vincit/objection.js/commit/46b842a6bc897198b83f41ac85c92864b991d7e9"
         }
      ]
   },
   "source":{
      "advisory":"c98e0f0e-ebf2-4072-be73-a1848ea031cc",
      "discovery":"EXTERNAL"
   }
}
