Описание
valib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspection functions provided by valib. Valib uses a built-in function (hasOwnProperty) from the unsafe user-input to examine an object. It is possible for a crafted payload to overwrite this function to manipulate the inspection results to bypass security checks.
Ссылки
- ExploitThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.0.0 (включая)
cpe:2.3:a:sideralis:valib.js:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 45%
0.00227
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-668
Связанные уязвимости
EPSS
Процентиль: 45%
0.00227
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-668