Junglewise Threat Intelligence

CVE-2018-3723: defaults-deep prototype pollution vulnerability

CVE-2018-3723 · Severity: low · CVSS 3 · Published 2018-07-26

Vendors: Jonschlinkert.

Executive brief

defaults-deep is a popular Node.js utility library for recursively merging object defaults. Versions before 0.2.4 are vulnerable to prototype pollution, a technique where attackers can modify the JavaScript Object prototype to inject malicious properties into all objects in an application. An attacker with the ability to control input to the library could poison the shared prototype and potentially execute arbitrary code or cause denial of service across the entire application.

Technical details

The vulnerability is a classic prototype pollution flaw (CWE-471) in the defaults-deep library's recursive object merging logic. The vulnerable code failed to exclude the special __proto__ property when copying object properties, allowing an attacker to pollute the Object prototype by providing specially crafted input objects. The fix (commit c873f34) adds an explicit check to skip the __proto__ key during property enumeration. The vulnerability requires the attacker to pass untrusted objects to the library's defaultsDeep() function, which may occur if the library processes user-supplied data. The attack does not require authentication or network access beyond what is needed to supply input to the vulnerable function.

Affected products

  • jonschlinkert defaults-deep before 0.2.4

Timeline

  • 2018-07-26: disclosed
  • 2018-07-26: patched: fixed in version 0.2.4

References