Lodash¿âÔÐÍÎÛȾÎó²î£¨CVE-2019-10744£©
Ðû²¼Ê±¼ä 2019-07-12
Åä¾°ÐÎò
Îó²îÁбí
Îó²îÆ·¼¶£º ¸ßΣ
CVSSÆÀ·Ö£º 7.3
Ó°Ïì¹æÄ££º 4.17.11֮ǰµÄËùÓа汾
Îó²îÏêÇé
ͨ¹ý½á¹¹º¯ÊýÖØÔØµÄ·½·¨£¬£¬£¬Lodash ¿âÖеĺ¯Êý defaultsDeep ºÜÓпÉÄܻᱻÓÕÆÌí¼Ó»òÐÞ¸Ä Object.prototype µÄÊôÐÔ£¬£¬£¬×îÖÕ¿ÉÄܵ¼Ö Web Ó¦ÓóÌÐòÍ߽⻣»ò¸Ä±äÆäÐÐΪ£¬£¬£¬Ïêϸȡ¾öÓÚÊÜÓ°ÏìµÄÓÃÀý¡£¡£¡£¡£¡£¡£
Pony by Snyk
ÔÐÍÎÛȾÊÇÒ»¸öÓ°Ïì JavaScript µÄÎó²î¡£¡£¡£¡£¡£¡£ÔÐÍÎÛȾÊÇÖ¸½«ÊôÐÔ×¢ÈëÏÖÓÐ JavaScript ÓïÑԽṹÔÐÍ£¨È繤¾ß£©µÄÄÜÁ¦¡£¡£¡£¡£¡£¡£JavaScript ÔÊÐíËùÓй¤¾ßÊôÐÔ±»¸ü¸Ä£¬£¬£¬ÀýÈçÈç_proto_£¬£¬£¬constructorºÍprototype¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ý×¢ÈëÆäËüÖµÀ´Ê¹ÓÃÕâЩÊôÐÔÀ´ÁýÕÖ»òÎÛȾ»ù´¡¹¤¾ßµÄ JavaScript Ó¦ÓóÌÐò¹¤¾ßÔÐÍ¡£¡£¡£¡£¡£¡£ÕâÑùºÜ¿ÉÄÜ»áÓ°ÏìÓ¦ÓóÌÐòͨ¹ýÔÐÍÁ´´¦Öóͷ£ JavaScript ¹¤¾ßµÄÀú³Ì£¬£¬£¬´Ó¶øµ¼Ö¾ܾøÐ§ÀÍ»òÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£
ÔÐÍÎÛȾµÄÁ½ÖÖÖ÷Òª·½·¨£º
²»Çå¾²µÄObjectµÝ¹éºÏ²¢
°´Â·¾¶½ç˵ÊôÐÔ
²»Çå¾²µÄ¹¤¾ßµÝ¹éºÏ²¢
Ò×Êܹ¥»÷µÄµÝ¹éºÏ²¢º¯ÊýµÄÂß¼×ñÕÕÒÔϸ߼¶Ä£×Ó£º

È»ºó¹¥»÷ÕßÔÚ Object ÔÐÍÉϸ´ÖÆÊôÐÔ¡£¡£¡£¡£¡£¡£
¿Ë¡²Ù×÷ÊÇÒ»¸öÌØÊâµÄ²»Çå¾²µÝ¹éºÏ²¢×ÓÀ࣬£¬£¬Ëü±¬·¢ÔÚ¶Ô¿Õ¹¤¾ß¾ÙÐеݹéºÏ²¢Ê±£ºmerge({},source)¡£¡£¡£¡£¡£¡£
lodash ºÍ Hoek ÊÇÒ×ÊܵݹéºÏ²¢¹¥»÷Ó°Ïì¡£¡£¡£¡£¡£¡£
°´Â·¾¶½ç˵ÊôÐÔ
ÈôÊǹ¥»÷Õß¿ÉÒÔ¿ØÖÆ¡°Â·¾¶¡±µÄÖµ£¬£¬£¬Ôò¿ÉÒÔ½«´ËÖµÉèÖÃΪ_proto_.myValue¡£¡£¡£¡£¡£¡£
·À·¶´ëÊ©
¶³½á Object.prototype £¬£¬£¬Ê¹ÔÐͲ»¿ÉÀ©³äÊôÐÔ
½¨Éè JSON schema
¹æ±Ü²»Çå¾²µÄµÝ¹éÐԺϲ¢º¯Êý
ʹÓÃÎÞÔÐ͹¤¾ß£¬£¬£¬Í»ÆÆÔÐÍÁ´²¢±ÜÃâÎÛȾ¡£¡£¡£¡£¡£¡£
½ÓÄÉÐ嵀 Map Êý¾ÝÀàÐÍ£¬£¬£¬È¡´ú Object ÀàÐÍ
ËäÈ»ÔÐÍÎÛȾÎó²îÓ°ÏìºÜÊÇÑÏÖØ£¬£¬£¬¿ÉÊǹ¥»÷ÕßÏëҪʹÓÃËü²¢Ã»ÓÐÄÇôÈÝÒ×£¬£¬£¬ËûÃÇÐèÒªÉîÈëÏàʶÿ¸ö Web Ó¦ÓõÄÊÂÇéÔÀí¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
²Î¿¼Á´½Ó
https://snyk.io/vuln/SNYK-JS-LODASH-450202
https://snyk.io/blog/snyk-research-team-discovers-severe-prototype-pollution-security-vulnerabilities-affecting-all-versions-of-lodash/
https://snyk-rules-pre-repository.s3.amazonaws.com/snapshots/master/patches/npm/lodash/20190702/lodash_20190702_0_0_1f8ea07746963a535385a5befc19fa687a627d2b.patch