HIGH
Prototype Pollution
Published May 1, 2022
8.1
HIGHCVSS 3.1
EPSS 1.84%
Description
All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if the top-level path contains __proto__, constructor or protorype. By crafting a malicious object, it is possible to bypass this check and achieve prototype pollution.
Affected products
- Vendor n/a Product Dset Defaultunknown
Affected
- ≥ 0, < unspecified
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Dset | unknown | Affected
|
- n/a
No data.
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/search-ui-rhel8
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/search-ui-rhel8 | Affected | n/a |
dset
npm
Introduced 0 Fixed 3.1.2org.webjars.npm:dset
Maven
Introduced 0 Fixed 3.1.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | dset | 0 | 3.1.2 |
| Maven | org.webjars.npm:dset | 0 | 3.1.2 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (12)
- https://access.redhat.com/security/cve/CVE-2022-25645 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2080847 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1897 Advisory
- https://github.com/advisories/GHSA-23wx-cgxq-vpwx Advisory
- https://github.com/lukeed/dset/blob/master/src/merge.js%23L9 Broken Link
- https://github.com/lukeed/dset/pull/38
- https://nvd.nist.gov/vuln/detail/CVE-2022-25645
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2431974
- https://security.snyk.io/vuln/SNYK-JS-DSET-2330881
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2431974 ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-DSET-2330881 ExploitThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-25645
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published May 1, 2022
Updated Sep 17, 2024
Reserved Feb 24, 2022
Link CVE-2022-25645
CISA Vulnrichment
No data
GitHub
Link GHSA-23WX-CGXQ-VPWX