Mozilla 的 Node-convict(版本 6.2.2 及更高版本)存在一个拒绝服务(DoS)漏洞,该漏洞源于 config.set() 函数中对原型污染(prototype pollution)的防护不完整。攻击者若能控制配置键名,便可以向 constructor.<key> 写入任意属性,而 walk() 函数会将此类键解析为全局 Object 函数。这将允许攻击者覆盖诸如 Object.assign 等核心 JavaScript 方法,从而导致进程范围内持续性的失败,并需重启进程才能恢复。 该漏洞绕过
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mozilla | Node-convict | 6.2.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet