Junglewise Threat Intelligence

CVE-2020-15256: object-path prototype pollution in set() method

CVE-2020-15256 · Severity: low · CVSS 3.1 · Published 2020-10-19

Technologies: object-path (npm). Vendors: npm.

Executive brief

object-path is a popular JavaScript library for accessing nested object properties. A prototype pollution vulnerability in its set() method could allow an attacker to modify the behavior of all objects in an application, potentially leading to authentication bypass, privilege escalation, or arbitrary code execution depending on how the application uses the affected code.

Technical details

The vulnerability is a prototype pollution flaw in the set() method of object-path versions <= 0.11.4. In versions >= 0.11.0, the vulnerability is limited to use of the includeInheritedProps mode, which must be explicitly enabled; in versions < 0.11.0, all usage of set() is vulnerable. An attacker can craft malicious input to pollute the Object prototype, affecting all objects in the runtime. The attack is network-reachable if the application accepts user-supplied input that flows to object-path's set() method. Patches are available in version 0.11.5 or later.

Affected products

  • npm object-path < 0.11.5

Timeline

  • 2020-10-19: disclosed
  • 2020-10-19: patched: Version 0.11.5 released

References

Related threats