Executive brief
A vulnerability exists in the @strikeentco/set library, a small utility used to set values in deeply nested JavaScript objects. An attacker can exploit this to manipulate the core structure of the application's data, potentially causing the service to crash or behave unpredictably. In certain configurations, this could also allow an attacker to execute unauthorized code on the server.
Technical details
The @strikeentco/set package is vulnerable to Prototype Pollution via the main export function. The vulnerability arises from an incomplete fix for a previous issue (CVE-2020-28267), where the library fails to properly sanitize property paths such as '__proto__'. By providing a specially crafted path, a remote attacker can inject properties into the global Object prototype. This can lead to a Denial of Service (DoS) by overwriting existing methods or, in specific application contexts where polluted properties are later evaluated, Remote Code Execution (RCE). The issue is fixed in version 1.0.2.
Affected products
- strikeentco @strikeentco/set < 1.0.2
Timeline
- 2020-11-11: disclosed: Original vulnerability (CVE-2020-28267) disclosed
- 2022-02-04: advisory: NVD published CVE-2021-23497 regarding the incomplete fix
- 2022-02-05: patched: Version 1.0.2 released with fix