Executive brief
The npm package rfc6902 is a library that implements RFC 6902 (JSON Patch operations). A prototype pollution vulnerability allows attackers to modify object prototype attributes through crafted input, potentially enabling code execution or behavior manipulation across applications using this library.
Technical details
This is a prototype pollution vulnerability (CWE-1321) in the rfc6902 npm package, specifically in the pointer.ts file. The vulnerability arises from improperly controlled modification of object prototype attributes during JSON Patch operations. The attack is network-accessible, requires no authentication or user interaction, and affects the confidentiality, integrity, and availability of affected systems. An attacker can exploit this by sending malicious JSON Patch payloads that pollute the prototype chain, leading to arbitrary code execution or denial of service. The vulnerability was patched in version 5.0.0 (commit c006ce9faa43d31edb34924f1df7b79c137096cf), and all versions prior to 5.0.0 are affected.
Affected products
- chbrown rfc6902 all versions before 5.0.0
Timeline
- 2021-08-06: disclosed: Vulnerability reported via Veracode scan
- 2022-12-15: patched: Fix applied in version 5.0.0
- 2022-12-15: advisory: GHSA-p495-jxh2-wrfg and CVE-2021-4245 published