PT-2022-11692 · Unknown · Starcounter-Jack Json-Patch
Alromh87
·
Published
2022-12-25
·
Updated
2024-05-17
·
CVE-2021-4279
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Starcounter-Jack JSON-Patch versions up to 3.1.0
Description
A vulnerability has been found in Starcounter-Jack JSON-Patch, classified as problematic. This issue affects unknown code and leads to improperly controlled modification of object prototype attributes, known as 'prototype pollution'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.1.1 can address this issue.
Recommendations
For Starcounter-Jack JSON-Patch versions up to 3.1.0, upgrade to version 3.1.1 to address the issue. As a temporary workaround, consider restricting access to the affected component until the upgrade is applied.
Exploit
Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Starcounter-Jack Json-Patch