PT-2023-8584 · Dot-Diver · Dot-Diver
D3Ng03
+1
·
Published
2023-11-03
·
Updated
2023-12-26
·
CVE-2023-45827
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
dot-diver versions prior to 1.0.2
Description
The issue is related to a Prototype Pollution vulnerability in the
setByPath function, which can lead to remote code execution (RCE). This vulnerability allows an attacker to modify object attributes, potentially enabling them to execute arbitrary code. The vulnerability is present in versions prior to 1.0.2 of the dot-diver library.Recommendations
For versions prior to 1.0.2, upgrade to release 1.0.2 or later to address the Prototype Pollution vulnerability in the
setByPath function. As a temporary workaround, consider restricting the use of the setByPath function until a patch is applied.Exploit
Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dot-Diver