Junglewise Threat Intelligence

CVE-2024-36581: Badger Database prototype pollution leading to arbitrary code execution

CVE-2024-36581 · Severity: low · CVSS 3.1 · Published 2024-06-17

Vendors: npm.

Executive brief

Badger Database is a JavaScript library used to provide database-like functionality in web applications. A prototype pollution vulnerability allows attackers with authenticated network access to modify core JavaScript object properties, leading to denial of service, cross-site scripting attacks, or arbitrary code execution in any application using this library.

Technical details

The vulnerability is a prototype pollution issue (CWE-1321, CWE-94) in the @abw/badger-database npm package version 1.2.1 and earlier. The vulnerable code in dist/badger-database.esm.js fails to sanitize user-supplied input passed to the setDebug() function, allowing an attacker to inject malicious JSON containing __proto__ or constructor.prototype properties. This pollutes Object.prototype, affecting all objects in the application's runtime. An authenticated attacker can leverage this to modify application logic, trigger denial of service, execute arbitrary code, or perform cross-site scripting attacks. No patch has been released; the maintainer recommends input validation and blocking requests containing __proto__ and constructor.prototype properties.

Affected products

  • abw badger-database 1.2.1 and earlier

Timeline

  • 2024-06-17: disclosed
  • 2024-06-17: advisory: CVE-2024-36581 published

References