We found results for “”
WS-2022-0363
Good to know:
Date: November 3, 2022
A prototype pollution vulnerability exists in Ember.js prior to 3.24.7, 3.28.10, 4.4.4, 4.8.1, and 4.9.0-beta.3. An attacker can set paths like __proto__.__proto__.isAdmin to mutate unexpected objects, including Javascript intrinsics like the global Object. Depending on the specifics of your application, this can be leveraged as part of an attack to steal user credentials.
Language: JS
Severity Score
Severity Score
Weakness Type (CWE)
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CWE-1321Top Fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | NONE |
Availability (A): | HIGH |