Lodash¿âÔÐÍÎÛȾÎó²î£¨CVE-2019-10744£©
Ðû²¼Ê±¼ä 2019-07-12
Åä¾°ÐÎò
Îó²îÁбí
Îó²îÆ·¼¶£º ¸ßΣ
CVSSÆÀ·Ö£º 7.3
Ó°Ïì¹æÄ££º 4.17.11֮ǰµÄËùÓа汾
Îó²îÏêÇé
ͨ¹ý½á¹¹º¯ÊýÖØÔصķ½·¨£¬Lodash ¿âÖеĺ¯Êý defaultsDeep ºÜÓпÉÄܻᱻÓÕÆÌí¼Ó»òÐÞ¸Ä Object.prototype µÄÊôÐÔ£¬×îÖÕ¿ÉÄܵ¼Ö Web Ó¦ÓóÌÐò±ÀÀ£»ò¸Ä±äÆäÐÐΪ£¬Ïêϸȡ¾öÓÚÊÜÓ°ÏìµÄÓÃÀý¡£
Pony by Snyk
ÔÐÍÎÛȾÊÇÒ»¸öÓ°Ïì JavaScript µÄÎó²î¡£ÔÐÍÎÛȾÊÇÖ¸½«ÊôÐÔ×¢ÈëÏÖÓÐ JavaScript ÓïÑԽṹÔÐÍ£¨È繤¾ß£©µÄÄÜÁ¦¡£JavaScript ÔÊÐíËùÓй¤¾ßÊôÐÔ±»¸ü¸Ä£¬ÀýÈçÈç_proto_£¬constructorºÍprototype¡£¹¥»÷Õßͨ¹ý×¢ÈëÆäËüÖµÀ´Ê¹ÓÃÕâЩÊôÐÔÀ´ÁýÕÖ»òÎÛȾ»ù´¡¹¤¾ßµÄ JavaScript Ó¦ÓóÌÐò¹¤¾ßÔÐÍ¡£ÕâÑùºÜ¿ÉÄÜ»áÓ°ÏìÓ¦ÓóÌÐòͨ¹ýÔÐÍÁ´´¦Öóͷ£ JavaScript ¹¤¾ßµÄÀú³Ì£¬´Ó¶øµ¼Ö¾ܾø·þÎñ»òÔ¶³Ì´úÂëÖ´ÐС£
ÔÐÍÎÛȾµÄÁ½ÖÖÖ÷Òª·½·¨£º
²»Çå¾²µÄObjectµÝ¹éºÏ²¢
°´Â·¾¶½ç˵ÊôÐÔ
²»Çå¾²µÄ¹¤¾ßµÝ¹éºÏ²¢
Ò×Êܹ¥»÷µÄµÝ¹éºÏ²¢º¯ÊýµÄÂß¼×ñÕÕÒÔϸ߼¶Ä£×Ó£º

È»ºó¹¥»÷ÕßÔÚ Object ÔÐÍÉϸ´ÖÆÊôÐÔ¡£
¿Ë¡²Ù×÷ÊÇÒ»¸öÌØÊâµÄ²»Çå¾²µÝ¹éºÏ²¢×ÓÀ࣬Ëü±¬·¢ÔÚ¶Ô¿Õ¹¤¾ß¾ÙÐеݹéºÏ²¢Ê±£ºmerge({},source)¡£
lodash ºÍ Hoek ÊÇÒ×ÊܵݹéºÏ²¢¹¥»÷Ó°Ïì¡£
°´Â·¾¶½ç˵ÊôÐÔ
ÈôÊǹ¥»÷Õß¿ÉÒÔ¿ØÖÆ¡°Â·¾¶¡±µÄÖµ£¬Ôò¿ÉÒÔ½«´ËÖµÉèÖÃΪ_proto_.myValue¡£
·À·¶´ëÊ©
¶³½á Object.prototype £¬Ê¹ÔÐͲ»¿ÉÀ©³äÊôÐÔ
½¨Éè JSON schema
¹æ±Ü²»Çå¾²µÄµÝ¹éÐԺϲ¢º¯Êý
ʹÓÃÎÞÔÐ͹¤¾ß£¬Í»ÆÆÔÐÍÁ´²¢±ÜÃâÎÛȾ¡£
½ÓÄÉÐ嵀 Map Êý¾ÝÀàÐÍ£¬È¡´ú Object ÀàÐÍ
ËäÈ»ÔÐÍÎÛȾÎó²îÓ°ÏìºÜÊÇÑÏÖØ£¬¿ÉÊǹ¥»÷ÕßÏëҪʹÓÃËü²¢Ã»ÓÐÄÇôÈÝÒ×£¬ËûÃÇÐèÒªÉîÈëÏàʶÿ¸ö Web Ó¦ÓõÄÊÂÇéÔÀí¡£
ÐÞ¸´½¨Òé
²Î¿¼Á´½Ó
https://snyk.io/vuln/SNYK-JS-LODASH-450202
https://snyk.io/blog/snyk-research-team-discovers-severe-prototype-pollution-security-vulnerabilities-affecting-all-versions-of-lodash/
https://snyk-rules-pre-repository.s3.amazonaws.com/snapshots/master/patches/npm/lodash/20190702/lodash_20190702_0_0_1f8ea07746963a535385a5befc19fa687a627d2b.patch