Lucene search

K
osvGoogleOSV:GHSA-WWXH-74FX-33C6
HistoryMay 01, 2023 - 2:01 p.m.

Possible prototype pollution in metadata record, when using meta decorator

2023-05-0114:01:02
Google
osv.dev
7
metadatarecord
meta decorator
prototype pollution
@aedart/support
vulnerability
sensitive object
patch
software

CVSS3

3.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

EPSS

0.001

Percentile

32.3%

Impact

Possible prototype pollution for the MetadataRecord, when merged with a base class’ metadata object, in meta decorator from the @aedart/support package.

The likelihood is questionable, given that a class’ metadata can only be set or altered when the class is decorated via meta(). Furthermore, object(s) of sensitive nature would have to be stored as metadata, before this can become a vulnerability.

Patches

Has been patched in version 0.6.1.

CVSS3

3.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

EPSS

0.001

Percentile

32.3%

Related for OSV:GHSA-WWXH-74FX-33C6