Lodash¿âÔÐÍ´«È¾·ì϶£¨CVE-2019-10744£©
°ä²¼¹¦·ò 2019-07-12

²¼¾°ÃèÊö
·ì϶Áбí
·ì϶µÈ¼¶£º ¸ßΣ
CVSSÆÀ·Ö£º 7.3
Ó°ÏìÁìÓò£º 4.17.11֮ǰµÄËùÓа汾
·ì϶ÏêÇé
ͨ¹ý»ú¹Øº¯Êý³ÁÔØµÄ·½Ê½£¬Lodash ¿âÖеĺ¯Êý defaultsDeep ºÜÓпÉÄܻᱻºýŪÔö³¤»òÅú¸Ä Object.prototype µÄÊôÐÔ£¬×îÖÕ¿ÉÄܵ¼Ö Web ÀûÓ÷¨Ê½±ÀÀ£»òŤתÆäÐÐΪ£¬¾ßÌåÈ¡¾öÓÚÊÜÓ°ÏìµÄÓÃÀý¡£
Pony by Snyk
ÔÐÍ´«È¾ÊÇÒ»¸öÓ°Ïì JavaScript µÄ·ì϶¡£ÔÐÍ´«È¾ÊÇÖ¸½«ÊôÐÔ×¢ÈëÏÖÓÐ JavaScript ˵»°»ú¹ØÔÐÍ£¨Èç¶ÔÏ󣩵ÄÄÜÁ¦¡£JavaScript ÔÊÐíËùÓжÔÏóÊôÐÔ±»¸ü¸Ä£¬ÀýÈçÈç_proto_£¬constructorºÍprototype¡£¹¥»÷Õßͨ¹ý×¢ÈëÆäËüÖ·´°Ñ³ÖÕâЩÊôÐÔÀ´¸²¸Ç»ò´«È¾»ù´¡¶ÔÏóµÄ JavaScript ÀûÓ÷¨Ê½¶ÔÏóÔÐÍ¡£ÕâÑùºÜ¿ÉÄÜ»áÓ°ÏìÀûÓ÷¨Ê½Í¨¹ýÔÐÍÁ´´¦Öà JavaScript ¶ÔÏóµÄ¹ý³Ì£¬´Ó¶øµ¼Ö»ؾø·þÎñ»òÔ¶³Ì´úÂëÖ´ÐС£
ÔÐÍ´«È¾µÄÁ½ÖÖÖØÒª·½Ê½£º
²»°²È«µÄObjectµÝ¹é¹é²¢
°´õè¾¶½ç˵ÊôÐÔ
²»°²È«µÄ¶ÔÏóµÝ¹é¹é²¢
Ò×Êܹ¥»÷µÄµÝ¹é¹é²¢º¯ÊýµÄÂß¼×ñÑÒÔϸ߼¶Ä£ÐÍ£º
¶øºó¹¥»÷ÕßÔÚ Object ÔÐÍÉϸ´ÔìÊôÐÔ¡£
¿Ë¡²Ù×÷ÊÇÒ»¸öÌØÊâµÄ²»°²È«µÝ¹é¹é²¢×ÓÀ࣬Ëü²úÉúÔÚ¶Ô¿Õ¶ÔÏó½øÐеݹé¹é²¢Ê±£ºmerge({},source)¡£
lodash ºÍ Hoek ÊÇÒ×Êܵݹé¹é²¢¹¥»÷Ó°Ïì¡£
°´õè¾¶½ç˵ÊôÐÔ
ÈôÊǹ¥»÷ÕßÄܹ»½ÚÔì¡°õè¾¶¡±µÄÖµ£¬ÔòÄܹ»½«´ËÖµÉèÖÃΪ_proto_.myValue¡£
·À·¶´ëÊ©
¶³½á Object.prototype £¬Ê¹ÔÐͲ»ÄÜÀ©³äÊôÐÔ
³ÉÁ¢ JSON schema
¶ã±Ü²»°²È«µÄµÝ¹éÐԹ鲢º¯Êý
ʹÓÃÎÞÔÐͶÔÏó£¬Í»ÆÆÔÐÍÁ´²¢Ô¤·À´«È¾¡£
ѡȡÐ嵀 Map Êý¾ÝÀàÐÍ£¬°ü°ì Object ÀàÐÍ
¹ÌÈ»ÔÐÍ´«È¾·ì϶ӰÏ켫¶ÈÑϳÁ£¬µ«Êǹ¥»÷ÕßÏëÒªÀûÓÃËü²¢Ã»ÓÐÄÇôÈÝÒ×£¬ËûÃDZØÒªÉî¿ÌÏàʼû¿¸ö Web ÀûÓõŤ×÷µÀÀí¡£
½¨¸´½¨Òé
²Î¿¼Á´½Ó
https://snyk.io/vuln/SNYK-JS-LODASH-450202
https://snyk.io/blog/snyk-research-team-discovers-severe-prototype-pollution-security-vulnerabilities-affecting-all-versions-of-lodash/
https://snyk-rules-pre-repository.s3.amazonaws.com/snapshots/master/patches/npm/lodash/20190702/lodash_20190702_0_0_1f8ea07746963a535385a5befc19fa687a627d2b.patch


¾©¹«Íø°²±¸11010802024551ºÅ