Skip to content

Conversation

@maximthomas
Copy link
Contributor

CVE-2024-38999 requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties

@maximthomas maximthomas requested a review from vharseko September 4, 2025 10:09
@vharseko vharseko merged commit 2f2879d into OpenIdentityPlatform:master Sep 5, 2025
19 of 34 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants