Dynamoosejs is a lightweight Node.js library that provides object modeling for Amazon DynamoDB, focusing on schema validation and data abstraction for a single product. The vendor's observed vulnerability profile centers on prototype pollution and related object-attribute manipulation flaws, which are characteristic of JavaScript libraries handling untrusted input without strict property access controls. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dynamoosejs over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-21304CRITICAL Dynamoose is an open-source modeling tool for Amazon's DynamoDB. In Dynamoose from version 2.0.0 and before version 2.7.0 there was a prototype pollution vulnerability in the inter | Feb 8, 2021 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dynamoosejs.
Media articles that mention a CVE ID that affects a product developed by Dynamoosejs — matched by CVE ID, not by vendor name.