A vulnerability was found in Yomguithereal Baobab up to 2.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack can be launched remotely. Upgrading to version 2.6.1 is able to address this issue. The patch is named c56639532a923d9a1600fb863ec7551b188b5d19. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217627.
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
Link | Tags |
---|---|
https://vuldb.com/?id.217627 | vdb entry third party advisory technical description |
https://vuldb.com/?ctiid.217627 | permissions required signature vdb entry third party advisory |
https://github.com/Yomguithereal/baobab/pull/511 | issue tracking exploit third party advisory patch |
https://github.com/Yomguithereal/baobab/commit/c56639532a923d9a1600fb863ec7551b188b5d19 | patch |
https://github.com/Yomguithereal/baobab/releases/tag/2.6.1 | patch release notes |