Executive brief
dottie is a JavaScript library for accessing and modifying nested object properties. Versions before 2.0.4 contain a prototype pollution vulnerability in the set() function that allows attackers to pollute the Object prototype without authentication or user interaction. An attacker can inject malicious properties into all JavaScript objects in an application, potentially causing denial of service or enabling other attacks depending on how the application uses polluted properties.
Technical details
The vulnerability is a prototype pollution weakness (CWE-1321) in dottie's set() function and related code in /dottie.js. The root cause is insufficient validation of property paths when setting nested object properties. An attacker can pass a path string containing __proto__ (e.g., "__proto__.test") to pollute the Object prototype. The attack is network-reachable with no authentication required and no user interaction needed—it depends only on the application calling dottie.set() or dottie.default() with untrusted input paths. Successful exploitation allows injection of arbitrary properties into all JavaScript objects, leading to denial of service (by breaking object methods like toString or valueOf), property injection attacks (e.g., privilege escalation), or remote code execution if the application evaluates polluted properties. The fix is available in version 2.0.4, which adds __proto__ guarding to the vulnerable code path.
Affected products
- mickhansen dottie <2.0.4
Timeline
- 2023-06-10: disclosed: Published by GitHub Advisory Database
- 2023-06-10: patched: Fix available in version 2.0.4