gettext-converter 提供了用于 JavaScript 的 gettext 资源转换工具。在 1.3.3 版本之前, 中的 函数使用 来分割嵌套的翻译键,其默认值为两个井号(#),并将每个片段直接用作动态对象键,且未过滤 、 或 。当应用程序转换不可信的 PO 或 i18next 翻译数据时,若其中包含 片段,该片段会被解析为 ,作为嵌套写入的目标,而 会将攻击者可控的翻译属性写入到整个进程范围的原型对象上。由此产生的原型污染可能导致服务拒绝(DoS),并可能引发依赖于具体应用的后续攻击。该问题已在
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| locize | gettext-converter | < 1.3.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| locize | gettext-converter | < 1.3.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet