Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

BalckDuck issue BDSA-2022-3013|CVE-2022-37598 #5781

Closed
kuzmenkovaES opened this issue Jan 18, 2023 · 1 comment
Closed

BalckDuck issue BDSA-2022-3013|CVE-2022-37598 #5781

kuzmenkovaES opened this issue Jan 18, 2023 · 1 comment

Comments

@kuzmenkovaES
Copy link

UglifyJS Vulnerable to Prototype Pollution via 'DEFNODE' Function

Uglify version 3.17.4

JavaScript input
There is the BlackDuck issue
BDSA BDSA-2022-3013
[CVE-2022-37598]
Published
Oct 24, 2022
Updated
Dec 19, 2022
The link to CVE https://nvd.nist.gov/vuln/detail/CVE-2022-37598
Description:

UglifyJS is vulnerable to prototype pollution through trusting unsanitized user input. A remote attacker could potentially leverage this to cause property injection, altering the flow of critical data throughout the application, a denial-of-service (DoS) or potentially execute arbitrary code depending on how objects are used by an application.

Note: The vendor disputes the validity of this vulnerability, asserting:

the methodsargument is always statically determined by the method calls that exist in ast.js and therefore always under the complete control of the authors of this library.

Снимок экрана 2023-01-19 в 00 38 28

Could you please fix the issue?
Please let me know if you need additional information.
Best regards,
Kate.

@alexlamsl
Copy link
Collaborator

#5699 (comment)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants