PT-2026-22065 · Dottie · Dottie
76Embiid21
·
Publicado
2023-06-10
·
Atualizado
2026-02-26
·
CVE-2026-27837
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
dottie versions 2.0.4 through 2.0.6
Description
dottie is a JavaScript library for nested object access and manipulation. Versions 2.0.4 through 2.0.6 contain an incomplete fix for a prototype pollution issue. The prototype pollution guard only validates the first segment of a dot-separated path, allowing attackers to bypass the protection by placing
proto at any position other than the first. The dottie.set() and dottie.transform() functions are affected. Versions prior to 2.0.4 are vulnerable due to insufficient checks within the set() function and the current variable in the /dottie.js file.Recommendations
Update to dottie version 2.0.7 or later.
Exploit
Correção
Prototype Pollution
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Dottie