PT-2023-8584 · Dot-Diver · Dot-Diver

D3Ng03

+1

·

Publicado

2023-11-03

·

Atualizado

2023-12-26

·

CVE-2023-45827

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions dot-diver versions prior to 1.0.2
Description The issue is related to a Prototype Pollution vulnerability in the setByPath function, which can lead to remote code execution (RCE). This vulnerability allows an attacker to modify object attributes, potentially enabling them to execute arbitrary code. The vulnerability is present in versions prior to 1.0.2 of the dot-diver library.
Recommendations For versions prior to 1.0.2, upgrade to release 1.0.2 or later to address the Prototype Pollution vulnerability in the setByPath function. As a temporary workaround, consider restricting the use of the setByPath function until a patch is applied.

Exploit

Correção

Prototype Pollution

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-01227
CVE-2023-45827
GHSA-9W5F-MW3P-PJ47

Produtos afetados

Dot-Diver