PT-2022-9014 · Furqan · Node-Whois
Zero734Kr
·
Published
2022-12-19
·
Updated
2022-12-29
·
CVE-2020-36618
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Furqan node-whois (affected versions not specified)
Description
A critical vulnerability has been found in Furqan node-whois, affecting an unknown function of the file index.coffee. The manipulation leads to improperly controlled modification of object prototype attributes, known as 'prototype pollution'. This issue can be exploited remotely.
Recommendations
To fix this issue, it is recommended to apply a patch with the name 46ccc2aee8d063c7b6b4dee2c2834113b7286076. As a temporary workaround, consider restricting access to the
index.coffee file until the patch is applied.Exploit
Fix
Prototype Pollution
Special Elements Injection
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Node-Whois