Returned-object prototype change via special-key assignment
Published May 10, 2022 · Updated Aug 4, 2024
Prototype poisoning in Ramda 0.27.0 and earlier allows remote attackers to alter application behavior through a crafted input object. mapObjIndexed copies each own input key into a plain accumulator with an acc[key] assignment, so an own proto key changes the returned object's prototype instead of creating an ordinary data property. Reachability depends on an application passing attacker-controlled objects to this function; Ramda disputes the security impact because the behavior creates a custom prototype only on the returned object.
Summary
What happened
Prototype poisoning in Ramda 0.27.0 and earlier allows remote attackers to alter application behavior through a crafted input object. mapObjIndexed copies each own input key into a plain accumulator with an acc[key] assignment, so an own proto key changes the returned object's prototype instead of creating an ordinary data property. Reachability depends on an application passing attacker-controlled objects to this function; Ramda disputes the security impact because the behavior creates a custom prototype only on the returned object.
The record
- CVE
- CVE-2021-42581
- Published
- May 10, 2022
- Updated
- Aug 4, 2024
- Vendor
- Unknown vendor
- Product
- Unknown product
- Classifications
- CWE-1321
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- May 10, 2022CVE publishedPublication date reported by the CVE source.
- Aug 4, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
What conditions does exploitation require?
What is affected?
Affected products and versions are unavailable in this record.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- mapObjIndexed prototype-poisoning JSFiddle demonstrationproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo