PT-2018-16152 · Npm · Hoek

Holyvier

·

Publicado

2018-03-30

·

Atualizado

2019-10-09

·

CVE-2018-3728

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions hoek versions prior to 4.2.1 hoek versions 5.0.x prior to 5.0.3
Description The issue affects the merge and applyToDefaults functions in the hoek node module, allowing a malicious user to modify the prototype of "Object" via proto. This can lead to the addition or modification of an existing property that will exist on all objects, potentially causing a denial of service. The vulnerability can be exploited when an unvalidated payload containing the proto property is provided to the affected functions.
Recommendations Update to version 4.2.1 or later. Update to version 5.0.3 or later.

Exploit

Correção

Prototype Pollution

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-3728
GHSA-JP4X-W63M-7WGM
RHSA-2018:1263

Produtos afetados

Hoek