Prototype pollution in dottie - CVE-2023-26132
Published: October 11, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The vulnerability exists due to prototype pollution flaw in the set() function in /dottie.js. A remote attacker can add or modify properties of Object.prototype using a __proto__ or constructor payload and perform prototype pollution, which can result in information disclosure or data manipulation.
Affected software
Ubuntu
Cloud Pak for Security (CP4S)
node-dottie (Ubuntu package)
How to mitigate CVE-2023-26132
Cloud Pak for Security (CP4S) - update to 1.10.14.0
node-dottie (Ubuntu package) - addressed in versions 2.0.2-1ubuntu0.1~esm1, 2.0.2-4ubuntu0.1~esm1