PT-2022-26043 · Unknown · Deep-Object-Diff

Carlos Bello

·

Published

2022-11-03

·

Updated

2022-11-05

·

CVE-2022-41713

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions deep-object-diff versions 1.1.0 through 1.1.5
Description The issue allows an external attacker to edit or add new properties to an object because the application does not properly validate incoming JSON keys, thus allowing the proto property to be edited.
Recommendations For deep-object-diff versions 1.1.0 through 1.1.5, update to version 1.1.6 or later to resolve the issue. As a temporary workaround, consider restricting the use of the proto property in incoming JSON keys until a patch is available.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2022-41713
GHSA-653V-RQX9-J85P

Affected Products

Deep-Object-Diff