PT-2021-24389 · Unknown · Think-Config
Published
2021-08-03
·
Updated
2021-08-03
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
think-config versions prior to 1.1.3
Description:
The software does not properly control modifications of attributes of the object prototype when receiving input from an upstream component. This issue may be related to the concept of prototype pollution, where an attacker can modify the prototype of an object, potentially leading to security vulnerabilities.
Recommendations:
For think-config versions prior to 1.1.3, upgrade to version 1.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable
think-config module to minimize the risk of exploitation.Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Think-Config