Skip to content

CVE-2024-38999 requirejs v2.3.6 was discovered to contain a prototype pollution #128

Merged
vharseko merged 2 commits intoOpenIdentityPlatform:masterfrom
maximthomas:issues/openam-913-update-requirejs
Sep 5, 2025
Merged

CVE-2024-38999 requirejs v2.3.6 was discovered to contain a prototype pollution #128
vharseko merged 2 commits intoOpenIdentityPlatform:masterfrom
maximthomas:issues/openam-913-update-requirejs

Conversation

@maximthomas
Copy link
Copy Markdown
Contributor

CVE-2024-38999 requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties

@maximthomas maximthomas requested a review from vharseko September 4, 2025 10:09
@vharseko vharseko merged commit 2f2879d into OpenIdentityPlatform:master Sep 5, 2025
19 of 34 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants