Junglewise Threat Intelligence

CVE-2019-18954: Pomelo critical state manipulation via attribute injection

CVE-2019-18954 · Severity: low · CVSS 3.1 · Published 2019-12-02

Vendors: npm.

Executive brief

Pomelo is a scalable game server framework for Node.js. An unauthenticated remote attacker can inject malicious attributes into user input to overwrite internal handler methods and attributes, allowing them to corrupt or disable game server functionality. For example, an attacker could overwrite the login handler to prevent all users from accessing the game server.

Technical details

The vulnerability is a CWE-668 (Exposure of Resource to Wrong Sphere) issue in Pomelo's entry handler (template/game-server/app/servers/connector/handler/entryHandler.js). The root cause is improper input validation and object property assignment—the handler fails to sanitize user input, allowing attackers to inject properties that overwrite critical handler methods. The attack is network-accessible (no authentication required) and requires no user interaction. An unauthenticated remote attacker can send a crafted request (e.g., via the connector RPC interface) with nested properties targeting the handler's constructor or methods, causing method overwriting and handler malfunction. The vulnerability was fixed in Pomelo v2.2.7; versions through 2.2.5 are affected.

Affected products

  • NetEase pomelo < 2.2.7

Timeline

  • 2019-12-02: disclosed
  • 2019: patched: Fixed in version 2.2.7

References