Junglewise Threat Intelligence

CVE-2021-39227: zrender prototype pollution in merge and clone helper methods

CVE-2021-39227 · Severity: low · CVSS 3.1 · Published 2021-09-20

Vendors: Apache.

Executive brief

zrender is a rendering library used by popular data visualization tools like Apache ECharts. A prototype pollution vulnerability in the merge and clone helper methods could allow an attacker to modify object prototypes, potentially affecting all objects created subsequently and compromising application behavior or data integrity.

Technical details

A prototype pollution vulnerability exists in the src/core/util.ts module of zrender, specifically in the merge and clone helper methods. The vulnerability arises from improper handling of user-supplied input when initializing or updating object properties, allowing manipulation of the Object prototype. No authentication or special privileges are required; the attack vector is local or context-dependent based on how the merge and clone functions are invoked. An attacker can pollute the prototype chain to inject or modify properties across all objects in the application. Patches were released in zrender 5.2.1 and 4.3.3, and users are advised to update accordingly, with ECharts users also updating to 5.2.1 if applicable.

Affected products

  • ecomfe zrender <= 5.2.0, <= 4.3.2; fixed in 5.2.1, 4.3.3
  • Apache ECharts affected versions using zrender <= 5.2.0; fixed in 5.2.1

Timeline

  • 2021-09-17: disclosed: Vulnerability disclosed via GitHub advisory
  • 2021-09-20: patched: Patches released: zrender 5.2.1 and 4.3.3

References