Junglewise Threat Intelligence

CVE-2024-30564: andrei-tatar nora-firebase-common prototype pollution in updateStateInternal

CVE-2024-30564 · Severity: critical · CVSS 9.8 · Published 2024-04-18

Vendors: npm.

Executive brief

A security vulnerability exists in the @andrei-tatar/nora-firebase-common library, which is used for integrating smart home devices with Firebase. An attacker can exploit this flaw to remotely execute unauthorized code on systems using the library. This could lead to a complete takeover of the affected service, potentially exposing sensitive user data or disrupting smart home operations.

Technical details

A prototype pollution vulnerability (CWE-1321) exists in @andrei-tatar/nora-firebase-common between versions 1.0.41 and 1.12.2. The flaw is located in the updateStateInternal method, where the updateState parameter is not properly validated. A remote, unauthenticated attacker can provide a specially crafted script or object that modifies the JavaScript object prototype. This modification can be leveraged to achieve remote code execution (RCE) in the context of the application. The issue has been addressed in version 1.12.3.

Affected products

  • andrei-tatar @andrei-tatar/nora-firebase-common >= 1.0.41, < 1.12.3

Timeline

  • 2024-04-18: disclosed
  • 2024-04-18: advisory
  • 2024-04-18: patched: Version 1.12.3 released

References