Security readout for executives and security teams
Plain-English summary
CVE-2021-23370 is a high-severity prototype pollution issue in Swiper before 6.5.1. For an organization, the main cited impact is availability: vulnerable applications may be destabilized if attacker-controlled input reaches the affected library path.
Executive priority
Treat this as a normal high-priority dependency remediation, not an emergency zero-day response. Prioritize internet-facing applications and shared frontend packages first, then complete transitive dependency cleanup through standard patch cycles.
Technical view
The source bundle identifies Swiper versions before 6.5.1 as affected by prototype pollution. The CVSS 3.1 vector is network-accessible, low complexity, no privileges, no user interaction, unchanged scope, and high availability impact only.
Likely exposure
Exposure is most likely in web applications or Java applications packaging Swiper through npm, Bower, or WebJars variants referenced by Snyk. Confirm both direct and transitive dependencies because the bundle does not enumerate exact vulnerable version ranges beyond before 6.5.1.
Exploitation context
The bundle marks KEV as false, so there is no provided evidence of known active exploitation. The CVSS vector includes proof-of-concept maturity, but the provided sources do not establish exploitation in the wild.
Researcher notes
The record is sparse: no CWE entry is listed, affected versions are described only as before 6.5.1, and impact is availability-only per CVSS. Avoid broad claims about confidentiality, integrity, or active exploitation without additional vendor evidence.
Mitigation direction
- Upgrade Swiper to 6.5.1 or later where it is directly used.
- Update WebJars, Bower, or npm package wrappers that embed vulnerable Swiper versions.
- Regenerate and redeploy application bundles after dependency updates.
- If upgrade is blocked, check Swiper and Snyk guidance; no workaround is named in the bundle.
Validation and detection
- Review package manifests and lockfiles for Swiper versions before 6.5.1.
- Check Java dependency trees for org.webjars Swiper packages referenced by Snyk.
- Verify deployed assets no longer include the vulnerable Swiper build.
- Run dependency scanning across JavaScript and Java package ecosystems.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-23370 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 7.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P3.93.6Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
7.5HighVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P
Source materials
- CVE List V5 sourceCVE List V5
- https://snyk.io/vuln/SNYK-JS-SWIPER-1088062CVE reference · x_refsource_MISC
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1244696CVE reference · x_refsource_MISC
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBNOLIMITS4WEB-1244697CVE reference · x_refsource_MISC
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1244698CVE reference · x_refsource_MISC
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1244699CVE reference · x_refsource_MISC
- https://github.com/nolimits4web/swiper/commit/9dad2739b7474f383474773d5ab898a0c29ac178CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
