Executive brief
A vulnerability exists in safe-flat, a software library used to convert flat data structures into nested objects. An attacker can exploit this to crash the application or potentially execute unauthorized commands on the server. This could lead to a total service outage or the compromise of sensitive data and internal systems.
Technical details
A prototype pollution vulnerability (CWE-1321) exists in the 'unflatten' function of the safe-flat library. The root cause is the improper validation of object keys such as '__proto__', 'constructor', and 'prototype' during the unflattening process. A remote, unauthenticated attacker can provide specially crafted input that modifies the base object prototype. This can lead to application-wide property injection, resulting in Denial of Service (DoS) or Remote Code Execution (RCE) depending on the application environment. The issue is fixed in version 2.0.2.
Affected products
- jessie-codes safe-flat 2.0.0 - 2.0.1
Timeline
- 2021-04-26: advisory: NVD published CVE-2021-25927
- 2021-05-20: patched: Fix committed to GitHub repository
- 2021-06-21: disclosed: GitHub Advisory published