Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4x6v-rwh4-55jw

Опубликовано: 02 дек. 2019
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Pomelo allows external control of critical state data

Pomelo v2.2.5 allows external control of critical state data. A malicious user input can corrupt arbitrary methods and attributes in template/game-server/app/servers/connector/handler/entryHandler.js because certain internal attributes can be overwritten via a conflicting name. Hence, a malicious attacker can manipulate internal attributes by adding additional attributes to user input.

Пакеты

Наименование

pomelo

npm
Затронутые версииВерсия исправления

< 2.2.7

2.2.7

EPSS

Процентиль: 62%
0.00429
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 5.3
nvd
около 6 лет назад

Pomelo v2.2.5 allows external control of critical state data. A malicious user input can corrupt arbitrary methods and attributes in template/game-server/app/servers/connector/handler/entryHandler.js because certain internal attributes can be overwritten via a conflicting name. Hence, a malicious attacker can manipulate internal attributes by adding additional attributes to user input.

EPSS

Процентиль: 62%
0.00429
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-668