Software Mansion React Native Worklets 在 0.12.2 版本之前存在原型链污染漏洞。攻击者可通过构造包含 属性的恶意对象,修改在 文件中 函数序列化过程中创建的对象的原型链。 当受污染的数据随后被 React Native Worklets 处理时,这种格式错误的序列化对象会导致 React Native 应用程序崩溃。在那些将攻击者可控数据通过受影响序列化路径传递的应用程序中,这可能引发远程触发的拒绝服务(DoS)攻击。对于持久化存储攻击者可控数据的应用程序,拒绝服务现象可
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| swmansion | React Native Reanimated | worklets-0.5.0< worklets-0.12.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| swmansion | React Native Reanimated | worklets-0.5.0 ~ worklets-0.12.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet