PT-2022-11920 · Unknown · Oroplatform
Rgrebenchuk
·
Published
2022-01-04
·
Updated
2022-01-12
·
CVE-2021-43852
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
OroPlatform versions prior to 4.2.8
Description
The issue allows an attacker to inject properties into existing JavaScript language construct prototypes, such as objects, by sending a specially crafted request. This injection may lead to JavaScript code execution by libraries that are vulnerable to Prototype Pollution.
Recommendations
For versions prior to 4.2.8, update to version 4.2.8 to resolve the issue.
As a temporary workaround, consider configuring a firewall or WAF to drop requests containing strings:
proto, constructor[prototype], and constructor.prototype to mitigate this issue.Fix
Special Elements Injection
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oroplatform