Executive brief
progressbar.js is a popular JavaScript library for displaying progress bars in web applications. A prototype pollution vulnerability in its extend() utility function allows attackers to inject arbitrary properties into JavaScript objects, potentially corrupting application behavior and causing service disruption or data manipulation.
Technical details
The vulnerability is a prototype pollution flaw in the extend() function within utils.js (CWE-1321) affecting all versions prior to 1.1.1. The function improperly merges user-supplied objects without sanitizing the __proto__ or constructor properties, allowing an attacker to pollute the Object prototype chain. This is triggered via network-based object manipulation with no authentication required. An attacker can poison shared object properties to corrupt the behavior of the application and other libraries that inherit from the polluted prototype, leading to denial of service or unauthorized behavior. The vulnerability was patched in version 1.1.1 by replacing the custom extend() implementation with lodash.merge.
Affected products
- Kim Mobrunfeldt progressbar.js <1.1.1
Timeline
- 2023-06-12: disclosed
- 2023-06-12: patched: Fixed in version 1.1.1