PT-2022-9014 · Furqan · Node-Whois

Zero734Kr

·

Published

2022-12-19

·

Updated

2022-12-29

·

CVE-2020-36618

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Furqan node-whois (affected versions not specified)
Description A critical vulnerability has been found in Furqan node-whois, affecting an unknown function of the file index.coffee. The manipulation leads to improperly controlled modification of object prototype attributes, known as 'prototype pollution'. This issue can be exploited remotely.
Recommendations To fix this issue, it is recommended to apply a patch with the name 46ccc2aee8d063c7b6b4dee2c2834113b7286076. As a temporary workaround, consider restricting access to the index.coffee file until the patch is applied.

Exploit

Fix

Prototype Pollution

Special Elements Injection

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36618
GHSA-97JV-C342-5XHC

Affected Products

Node-Whois