PT-2022-17573 · Sds · Sds

Cristian-Alexandru Staicu

+3

·

Published

2022-05-13

·

Updated

2022-05-24

·

CVE-2022-25862

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions sds versions 0.0.0 and later
Description The issue allows the library to be tricked into adding or modifying properties of the Object.prototype. This is achieved by abusing the set function located in js/set.js.
Recommendations For sds version 0.0.0, consider restricting access to the set function in js/set.js to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-25862
GHSA-PH28-WWFJ-FV7F
SNYK-JS-SDS-2385944

Affected Products

Sds