Executive brief
Badger Database is a JavaScript library used to provide database-like functionality in web applications. A prototype pollution vulnerability allows attackers with authenticated network access to modify core JavaScript object properties, leading to denial of service, cross-site scripting attacks, or arbitrary code execution in any application using this library.
Technical details
The vulnerability is a prototype pollution issue (CWE-1321, CWE-94) in the @abw/badger-database npm package version 1.2.1 and earlier. The vulnerable code in dist/badger-database.esm.js fails to sanitize user-supplied input passed to the setDebug() function, allowing an attacker to inject malicious JSON containing __proto__ or constructor.prototype properties. This pollutes Object.prototype, affecting all objects in the application's runtime. An authenticated attacker can leverage this to modify application logic, trigger denial of service, execute arbitrary code, or perform cross-site scripting attacks. No patch has been released; the maintainer recommends input validation and blocking requests containing __proto__ and constructor.prototype properties.
Affected products
- abw badger-database 1.2.1 and earlier
Timeline
- 2024-06-17: disclosed
- 2024-06-17: advisory: CVE-2024-36581 published