mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-29 09:41:05 +00:00
973 B
973 B
CVE-2022-25645
Description
All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if the top-level path contains proto, constructor or protorype. By crafting a malicious object, it is possible to bypass this check and achieve prototype pollution.
POC
Reference
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2431974
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2431974
- https://snyk.io/vuln/SNYK-JS-DSET-2330881
- https://snyk.io/vuln/SNYK-JS-DSET-2330881
Github
No PoCs found on GitHub currently.