Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Rollbar.js Prototype Pollution Vulnerability in merge()
Vulnerability Description
Rollbar.js offers error tracking and logging from Javascript to Rollbar. In versions before 2.26.5 and from 3.0.0-alpha1 to before 3.0.0-beta5, there is a prototype pollution vulnerability in merge(). If application code calls rollbar.configure() with untrusted input, prototype pollution is possible. This issue has been fixed in versions 2.26.5 and 3.0.0-beta5. A workaround involves ensuring that values passed to rollbar.configure() do not contain untrusted input.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
CWE-1321
Vulnerability Title
Rollbar.js 安全漏洞
Vulnerability Description
Rollbar.js是Rollbar开源的一个从错误跟踪和日志记录库。 Rollbar.js 2.26.5之前版本和3.0.0-alpha1至3.0.0-beta5之前版本存在安全漏洞,该漏洞源于merge函数存在原型污染,可能导致恶意输入污染原型链。
CVSS Information
N/A
Vulnerability Type
N/A