PT-2024-20341 · Unknown · @Blackprint/Engine

Mestrtee

·

Published

2024-05-20

·

Updated

2024-07-03

·

CVE-2024-24294

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions @blackprint/engine versions 0.8.12 through 0.9.1
Description A Prototype Pollution issue allows an attacker to execute arbitrary code via the utils.setDeepProperty function of engine.min.js. This issue enables the execution of arbitrary code, potentially leading to severe security consequences.
Recommendations For @blackprint/engine versions 0.8.12 through 0.9.1, consider disabling the utils.setDeepProperty function as a temporary workaround until a patch is available. Restrict access to the engine.min.js file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Prototype Pollution

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-24294
GHSA-G3Q2-VCJQ-RGRC

Affected Products

@Blackprint/Engine