Metrics
Affected Vendors & Products
Thu, 24 Jul 2025 05:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Versions of the package bun before 1.1.30 are vulnerable to Prototype Pollution due to improper input sanitization. An attacker can exploit this vulnerability through Bun's APIs that accept objects. | Versions of the package bun after 0.0.12 and before 1.1.30 are vulnerable to Prototype Pollution due to improper input sanitization. An attacker can exploit this vulnerability through Bun's APIs that accept objects. **Note:** This issue relates to the widely known and actively developed 'Bun' JavaScript runtime. The bun package on NPM at versions 0.0.12 and below belongs to a different and older project that happened to claim the 'bun' name in the past. |
Mon, 14 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Wed, 18 Dec 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 18 Dec 2024 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Versions of the package bun before 1.1.30 are vulnerable to Prototype Pollution due to improper input sanitization. An attacker can exploit this vulnerability through Bun's APIs that accept objects. | |
Weaknesses | CWE-1321 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: snyk
Published: 2024-12-18T06:06:03.597Z
Updated: 2025-07-24T04:34:32.456Z
Reserved: 2023-12-22T12:33:20.128Z
Link: CVE-2024-21548

Updated: 2024-12-18T15:03:24.885Z

Status : Awaiting Analysis
Published: 2024-12-18T06:15:23.360
Modified: 2025-07-24T07:15:51.057
Link: CVE-2024-21548

No data.