PT-2023-8584 · Dot-Diver · Dot-Diver

D3Ng03

+1

·

Published

2023-11-03

·

Updated

2023-12-26

·

CVE-2023-45827

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions dot-diver versions prior to 1.0.2
Description The issue is related to a Prototype Pollution vulnerability in the setByPath function, which can lead to remote code execution (RCE). This vulnerability allows an attacker to modify object attributes, potentially enabling them to execute arbitrary code. The vulnerability is present in versions prior to 1.0.2 of the dot-diver library.
Recommendations For versions prior to 1.0.2, upgrade to release 1.0.2 or later to address the Prototype Pollution vulnerability in the setByPath function. As a temporary workaround, consider restricting the use of the setByPath function until a patch is applied.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

BDU:2024-01227
CVE-2023-45827
GHSA-9W5F-MW3P-PJ47

Affected Products

Dot-Diver