Junglewise Threat Intelligence

CVE-2020-7618: sds prototype pollution

CVE-2020-7618 · Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The sds JavaScript library provides functions to manipulate object properties via keypaths. A prototype pollution vulnerability in the set function allows attackers to modify the prototype chain of JavaScript objects, potentially adding or altering properties that affect all objects in an application. This could lead to unexpected behavior, bypass of security checks, or denial of service depending on how the library is used.

Technical details

The vulnerability is a prototype pollution flaw (CWE-915) in the set function of the sds library. The vulnerable code attempts to block modifications via the literal string '__proto__' but does not account for alternative prototype pollution vectors such as 'constructor' or 'prototype' properties. An attacker with the ability to pass untrusted keypaths to the set function can inject malicious property assignments that modify the Object prototype, affecting all objects in the application. The attack requires network access and the ability to control the keypath parameter passed to the vulnerable function. The fix is available in version 4.0.0 and later.

Affected products

  • sds before 4.0.0

Timeline

  • 2020-04-07: disclosed: Published on NVD
  • 2020-08-31: advisory: GitHub reviewed the advisory
  • 2020-09-03: patched: Advisory published; fix available in version 4.0.0

References

Related threats