Prototype pollution in plotly.js - CVE-2023-46308
Published: February 13, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The vulnerability exists due to plot API calls have a risk of __proto__ being polluted in expandObjectPaths or nestedProperty. A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in information disclosure or data manipulation.
Affected software
DataPower Operations Dashboard
QRadar Suite
QRadar Pulse App
IBM Maximo Asset Management
How to mitigate CVE-2023-46308
DataPower Operations Dashboard - update to 1.0.20.1
QRadar Suite - update to 1.10.18.0
QRadar Pulse App - update to 2.2.12
IBM Maximo Asset Management - update to 7.6.1.3.25