Junglewise Threat Intelligence

CVE-2022-21213: mout prototype pollution in deepFillIn and deepMixIn

CVE-2022-21213 · Severity: low · CVSS 3.1 · Published 2022-06-18

Vendors: npm.

Executive brief

mout is a JavaScript utility library that provides object manipulation functions. This vulnerability allows attackers to pollute the prototype of JavaScript objects through the deepFillIn and deepMixIn functions, potentially affecting all JavaScript code that relies on mout, leading to unexpected behavior, denial of service, or application compromise depending on how the library is used.

Technical details

The vulnerability is a prototype pollution flaw in the deepFillIn and deepMixIn functions of the mout library. These functions recursively merge or fill object properties but fail to validate keys during recursive traversal, allowing an attacker to inject properties into Object.prototype. This is an incomplete fix of CVE-2020-7792. The vulnerability is network-accessible if the application processes untrusted input through these functions. An attacker can craft malicious input containing prototype-polluting keys (such as "__proto__" or "constructor") to modify the prototype chain, affecting all objects in the application. A patch is available in version 1.2.4 and later.

Affected products

  • mout mout < 1.2.4

Timeline

  • 2022-06-18: disclosed
  • 2022-09-19: patched: Fixed in version 1.2.4
  • 2022-06-20: other: GitHub security advisory reviewed

References

Related threats