Junglewise Threat Intelligence

CVE-2021-23507: object-path-set prototype pollution via setPath

CVE-2021-23507 · Severity: low · CVSS 3.1 · Published 2022-02-05

Vendors: npm.

Executive brief

object-path-set is a JavaScript utility library used to set nested properties in objects. The library is vulnerable to prototype pollution, a type of attack where an attacker can inject malicious properties into JavaScript's core Object prototype, affecting all objects in an application. An attacker exploiting this flaw could cause denial of service or modify application behavior in unexpected ways.

Technical details

The vulnerability is a prototype pollution flaw (CWE-1321) in the setPath method of object-path-set before version 1.0.2. The method fails to properly validate or sanitize path inputs, allowing an attacker to manipulate object prototypes by crafting specially formatted paths. This vulnerability can be triggered remotely via network if the affected library is used in a web service, with no authentication required. An attacker can merge object prototypes into the target, potentially achieving denial of service or arbitrary code execution depending on application context. The fix was released in version 1.0.2.

Affected products

  • skratchdot object-path-set before 1.0.2

Timeline

  • 2022-02-05: disclosed
  • 2022-02-05: patched: Fixed in version 1.0.2

References