PT-2019-12022 · Npm+4 · Mixin-Deep+4
CVE-2019-10746
·
Publicado
2019-08-23
·
Atualizado
2022-10-29
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
mixin-deep versions prior to 1.3.2
mixin-deep versions prior to 2.0.1
Description
The issue concerns Prototype Pollution, where the
mixin-deep function can be tricked into adding or modifying properties of Object.prototype using a constructor payload. This allows attackers to modify the prototype of Object, causing the addition or modification of an existing property on all objects. The mixinDeep function fails to validate which Object properties it updates.Recommendations
If you are using
mixin-deep 2.x, upgrade to version 2.0.1 or later.
If you are using mixin-deep 1.x, upgrade to version 1.3.2 or later.Exploit
Correção
Argument Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Almalinux
Centos
Red Hat
Rocky Linux
Mixin-Deep