ag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
📦
ag-grid
Vendor: ag-grid
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
2
Remote Access
Total CVEs
3
Total Indexed
Avg. EPSS
1.00%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
6.3
CVSS
CVE-2024-39001
RCE
Severity: MEDIUM
9.8
CVSS
CVE-2024-38996
RCE
ag-grid-community v31.3.2 and ag-grid-enterprise v31.3.2 were discovered to contain a prototype pollution via the _.mergeDeep function. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
Severity: CRITICAL
6.1
CVSS
ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angular Expressions, if AngularJS is used in combination with ag-grid.
Severity: MEDIUM