Vulnerability Description
An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __proto__, and Object.assign components. NOTE: this is disputed by the Supplier who does not agree it is a prototype pollution vulnerability.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://discord.com/assets/oneTrust/v4/scripttemplates/6.33.0/otBannerSdk.js
- https://github.com/brotheralameen1/Discordforschool/security/advisories/GHSA-63x
- https://packetstorm.news/files/id/201222/
FAQ
What is CVE-2024-57708?
CVE-2024-57708 is a vulnerability with a CVSS score of 5.7 (MEDIUM). An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __proto__, and Object.assign components. NOTE: this is disputed by the Supplier wh...
How severe is CVE-2024-57708?
CVE-2024-57708 has been rated MEDIUM with a CVSS base score of 5.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-57708?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.