Junglewise Threat Intelligence

CVE-2024-38994: @amoy/common prototype pollution in extend function

CVE-2024-38994 · Severity: low · CVSS 3.1 · Published 2024-07-01

Vendors: npm.

Executive brief

@amoy/common is a JavaScript utility library used by Node.js and web applications. A prototype pollution vulnerability in its extend function allows attackers to modify core JavaScript object behavior by injecting malicious properties, potentially leading to denial of service, remote code execution, or cross-site scripting attacks depending on how the application uses the affected library.

Technical details

This is a prototype pollution vulnerability (CWE-1321) in the extend and setValue functions of @amoy/common v1.0.10. An attacker can craft a malicious object containing __proto__ properties and pass it to the vulnerable functions to pollute Object.prototype, modifying the behavior of all objects inheriting from that prototype. The attack requires network access and can be triggered without authentication or user interaction. Successful exploitation can lead to arbitrary code execution or denial of service depending on application logic and available gadget chains. A patch should sanitize inputs to prevent __proto__ injection.

Affected products

  • amoyjs @amoy/common 1.0.10

Timeline

  • 2024-07-01: disclosed: Public disclosure via GHSA-w58v-r3cp-qr93
  • 2024-07-01: other: NVD published CVE-2024-38994

References