{"id":"CVE-2021-20083","details":"Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object 2.2.3 allows a malicious user to inject properties into Object.prototype.","aliases":["GHSA-q9xg-h756-8689"],"modified":"2026-07-08T21:26:37.169566Z","published":"2021-04-23T19:15:09.163Z","references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7CR6VGITIB2TXXZ6B5QRRWPU5S4BXQPD/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IJX6NVXSRN3RX3YUVEJQ4WUTQSDL3DSR/"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/166299/WordPress-Core-5.9.0-5.9.1-Cross-Site-Scripting.html"},{"type":"EVIDENCE","url":"https://github.com/BlackFan/client-side-prototype-pollution/blob/master/pp/jquery-query-object.md"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/alrusdi/jquery-plugin-query-object","events":[{"introduced":"19104670bac1a769f4927390777bb3a4cc60f17a"},{"last_affected":"19104670bac1a769f4927390777bb3a4cc60f17a"}],"database_specific":{"cpe":"cpe:2.3:a:jquery-plugin-query-object_project:jquery-plugin-query-object:2.2.3:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.2.3"},{"last_affected":"2.2.3"}],"source":"CPE_STRING"}}],"versions":["2.2.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-20083.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}