Junglewise Threat Intelligence

CVE-2024-38992: airvertco frappejs prototype pollution in registerView

CVE-2024-38992 · Severity: low · CVSS 3.1 · Published 2024-07-01

Vendors: npm.

Executive brief

frappejs is a JavaScript library used to build web applications with data management capabilities. A prototype pollution vulnerability in the registerView function allows an authenticated attacker to modify the behavior of all objects in the application, potentially leading to arbitrary code execution, denial of service, or other attacks depending on how the application uses affected objects.

Technical details

The vulnerability is a prototype pollution flaw (CWE-1321) in the registerView function of @airvertco/frappejs version 0.0.11. An attacker can inject arbitrary properties into Object.prototype by passing specially crafted arguments containing the __proto__ property to registerView. The attack requires the attacker to be able to call the registerView function, typically requiring some level of application access or network reachability. Successful exploitation can cascade into remote code execution, denial of service, or cross-site scripting depending on gadgets present in the application. No patch information is currently available in the advisory.

Affected products

  • airvertco frappejs 0.0.11

Timeline

  • 2024-07-01: disclosed
  • 2024-07-01: other: CVE-2024-38992 assigned

References