PT-2022-11920 · Unknown · Oroplatform

Rgrebenchuk

·

Published

2022-01-04

·

Updated

2022-01-12

·

CVE-2021-43852

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions OroPlatform versions prior to 4.2.8
Description The issue allows an attacker to inject properties into existing JavaScript language construct prototypes, such as objects, by sending a specially crafted request. This injection may lead to JavaScript code execution by libraries that are vulnerable to Prototype Pollution.
Recommendations For versions prior to 4.2.8, update to version 4.2.8 to resolve the issue. As a temporary workaround, consider configuring a firewall or WAF to drop requests containing strings: proto, constructor[prototype], and constructor.prototype to mitigate this issue.

Fix

Special Elements Injection

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-43852
GHSA-JX5Q-G37M-H5HJ

Affected Products

Oroplatform