在 alibaba-fusion-next 1.27.34 及更早版本中发现了一个安全漏洞。该问题影响了 components/dialog/index.tsx 文件中 ConfigProvider.getContextProps 函数的 deepMerge 组件实现。通过对参数 locale 进行操控,可导致对象原型属性被不受控地修改。此攻击可由远程触发。该 GitHub 问题因长期无活动而自动关闭。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| alibaba-fusion | next | 1.27.0 |
cpe:2.3:a:next:next:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet