dot-access 1.0.0 存在一个原型污染漏洞,攻击者可以通过向 set() 方法提供精心构造的点分路径来修改 Object.prototype。如果攻击者能够控制路径(例如通过用户提供的字段名),他们就可以利用 __proto__ 段向所有对象注入属性,从而更改授权标志和默认选项,或者导致进程崩溃。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ntharim | dot-access | ≤ 1.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ntharim | dot-access | 0 ~ 1.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet