CVE-2020-15256
published 2020-10-19CVE-2020-15256: A prototype pollution vulnerability has been found in `object-path` = 0.11.0 is used), which has to be explicitly enabled by creating a new instance of…
PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.55%
72.5th percentile
A prototype pollution vulnerability has been found in `object-path` = 0.11.0 is used), which has to be explicitly enabled by creating a new instance of `object-path` and setting the option `includeInheritedProps: true`, or by using the default `withInheritedProps` instance. The default operating mode is not affected by the vulnerability if version >= 0.11.0 is used. Any usage of `set()` in versions = 0.11.0.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | node-object-path | < node-object-path 0.11.5-3 (bookworm) | node-object-path 0.11.5-3 (bookworm) |
| debian | node-object-path | < node-object-path 0.11.7-1 (bookworm) | node-object-path 0.11.7-1 (bookworm) |
| object-path_project | object-path | < 0.11.6 | 0.11.6 |
| object-path_project | object-path | < 0.11.5 | 0.11.5 |
| object-path_project | object-path | >= 0 < 0.11.5 | 0.11.5 |
| object-path_project | object-path | >= 0 < 0.11.6 | 0.11.6 |
| object-path_project | object-path | >= unspecified < 0.11.6 | 0.11.6 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa9.8CRITICAL
osv9.8CRITICAL
vendor_debian7.7HIGH
vendor_redhat7.7HIGH
vendor_ubuntu7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
object-path vulnerabilities
vendor_ubuntu·2023-03-22·CVSS 7.7
CVE-2021-3805 [HIGH] object-path vulnerabilities
Title: object-path vulnerabilities
Summary: Several security issues were fixed in object-path.
It was discovered that the set() method in object-path could be corrupted
as a result of prototype pollution by sending a message to the parent
process. An attacker could use this issue to cause object-path to crash.
(CVE-2020-15256, CVE-2021-23434, CVE-2021-3805)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
object-path: Type confusion vulnerability can lead to a bypass of CVE-2020-15256
vendor_redhat·2021-08-27·CVSS 7.7
CVE-2021-23434 [HIGH] CWE-843 object-path: Type confusion vulnerability can lead to a bypass of CVE-2020-15256
object-path: Type confusion vulnerability can lead to a bypass of CVE-2020-15256
This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components used in the path parameter are arrays. In particular, the condition currentPath === '__proto__' returns false if currentPath is ['__proto__']. This is because the === operator returns always false when the type of the operands is different.
Prototype pollution has been discovered in object-path NodeJS library. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components used in the path parameter are arrays. In particular, the condition currentPath === '__proto__' returns false if currentPath is ['__proto__']. This is because the
Debian
CVE-2021-23434: node-object-path - This affects the package object-path before 0.11.6. A type confusion vulnerabili...
vendor_debian·2021·CVSS 7.7
CVE-2021-23434 [HIGH] CVE-2021-23434: node-object-path - This affects the package object-path before 0.11.6. A type confusion vulnerabili...
This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components used in the path parameter are arrays. In particular, the condition currentPath === '__proto__' returns false if currentPath is ['__proto__']. This is because the === operator returns always false when the type of the operands is different.
Scope: local
bookworm: resolved (fixed in 0.11.7-1)
bullseye: resolved (fixed in 0.11.5-3+deb11u1)
forky: resolved (fixed in 0.11.7-1)
sid: resolved (fixed in 0.11.7-1)
trixie: resolved (fixed in 0.11.7-1)
Red Hat
object-path: Prototype pollution could result in DoS or RCE
vendor_redhat·2020-10-20·CVSS 7.7
CVE-2020-15256 [HIGH] CWE-915 object-path: Prototype pollution could result in DoS or RCE
object-path: Prototype pollution could result in DoS or RCE
A prototype pollution vulnerability has been found in `object-path` = 0.11.0 is used), which has to be explicitly enabled by creating a new instance of `object-path` and setting the option `includeInheritedProps: true`, or by using the default `withInheritedProps` instance. The default operating mode is not affected by the vulnerability if version >= 0.11.0 is used. Any usage of `set()` in versions = 0.11.0.
A flaw was found in object-path. A prototype pollution vulnerability has been found in `object-path` affecting the `set()` method. The vulnerability is limited to the `includeInheritedProps` mode (if version >= 0.11.0 is used), which has to be explicitly enabled by creating a new instance of `object-path` and setting the opt
Debian
CVE-2020-15256: node-object-path - A prototype pollution vulnerability has been found in `object-path` <= 0.11.4 af...
vendor_debian·2020·CVSS 7.7
CVE-2020-15256 [HIGH] CVE-2020-15256: node-object-path - A prototype pollution vulnerability has been found in `object-path` <= 0.11.4 af...
A prototype pollution vulnerability has been found in `object-path` = 0.11.0 is used), which has to be explicitly enabled by creating a new instance of `object-path` and setting the option `includeInheritedProps: true`, or by using the default `withInheritedProps` instance. The default operating mode is not affected by the vulnerability if version >= 0.11.0 is used. Any usage of `set()` in versions = 0.11.0.
Scope: local
bookworm: resolved (fixed in 0.11.5-3)
bullseye: resolved (fixed in 0.11.5-3)
forky: resolved (fixed in 0.11.5-3)
sid: resolved (fixed in 0.11.5-3)
trixie: resolved (fixed in 0.11.5-3)
OSV
node-object-path vulnerabilities
osv·2023-03-22·CVSS 9.8
CVE-2020-15256 [CRITICAL] node-object-path vulnerabilities
node-object-path vulnerabilities
It was discovered that the set() method in object-path could be corrupted
as a result of prototype pollution by sending a message to the parent
process. An attacker could use this issue to cause object-path to crash.
(CVE-2020-15256, CVE-2021-23434, CVE-2021-3805)
OSV
Prototype Pollution in object-path
osv·2021-09-01·CVSS 9.8
CVE-2021-23434 [CRITICAL] Prototype Pollution in object-path
Prototype Pollution in object-path
This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components used in the path parameter are arrays. In particular, the condition `currentPath === '__proto__'` returns false if `currentPath` is `['__proto__']`. This is because the `===` operator returns always false when the type of the operands is different.
GHSA
Prototype Pollution in object-path
ghsa·2021-09-01·CVSS 9.8
CVE-2021-23434 [CRITICAL] CWE-1321 Prototype Pollution in object-path
Prototype Pollution in object-path
This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components used in the path parameter are arrays. In particular, the condition `currentPath === '__proto__'` returns false if `currentPath` is `['__proto__']`. This is because the `===` operator returns always false when the type of the operands is different.
OSV
CVE-2021-23434: This affects the package object-path before 0
osv·2021-08-27·CVSS 9.8
CVE-2021-23434 [CRITICAL] CVE-2021-23434: This affects the package object-path before 0
This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-15256 when the path components used in the path parameter are arrays. In particular, the condition currentPath === '__proto__' returns false if currentPath is ['__proto__']. This is because the === operator returns always false when the type of the operands is different.
OSV
Prototype pollution in object-path
osv·2020-10-19
CVE-2020-15256 [HIGH] Prototype pollution in object-path
Prototype pollution in object-path
### Impact
A prototype pollution vulnerability has been found in `object-path` = 0.11.0 is used), which has to be explicitly enabled by creating a new instance of `object-path` and setting the option `includeInheritedProps: true`, or by using the default `withInheritedProps` instance. The default operating mode is not affected by the vulnerability if version >= 0.11.0 is used. Any usage of `set()` in versions = 0.11.5
### Workarounds
Don't use the `includeInheritedProps: true` options or the `withInheritedProps` instance if using a version >= 0.11.0.
### References
[Read more about the prototype pollution vulnerability](https://codeburst.io/what-is-prototype-pollution-49482fc4b638)
### For more information
If you have any questions or comments about t
OSV
CVE-2020-15256: A prototype pollution vulnerability has been found in `object-path` = 0
osv·2020-10-19·CVSS 9.8
CVE-2020-15256 [CRITICAL] CVE-2020-15256: A prototype pollution vulnerability has been found in `object-path` = 0
A prototype pollution vulnerability has been found in `object-path` = 0.11.0 is used), which has to be explicitly enabled by creating a new instance of `object-path` and setting the option `includeInheritedProps: true`, or by using the default `withInheritedProps` instance. The default operating mode is not affected by the vulnerability if version >= 0.11.0 is used. Any usage of `set()` in versions = 0.11.0.
GHSA
Prototype pollution in object-path
ghsa·2020-10-19
CVE-2020-15256 [HIGH] CWE-20 Prototype pollution in object-path
Prototype pollution in object-path
### Impact
A prototype pollution vulnerability has been found in `object-path` = 0.11.0 is used), which has to be explicitly enabled by creating a new instance of `object-path` and setting the option `includeInheritedProps: true`, or by using the default `withInheritedProps` instance. The default operating mode is not affected by the vulnerability if version >= 0.11.0 is used. Any usage of `set()` in versions = 0.11.5
### Workarounds
Don't use the `includeInheritedProps: true` options or the `withInheritedProps` instance if using a version >= 0.11.0.
### References
[Read more about the prototype pollution vulnerability](https://codeburst.io/what-is-prototype-pollution-49482fc4b638)
### For more information
If you have any questions or comments about t
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/mariocasciaro/object-path/commit/2be3354c6c46215c7635eb1b76d80f1319403c68https://github.com/mariocasciaro/object-path/security/advisories/GHSA-cwx2-736x-mf6whttps://github.com/mariocasciaro/object-path/commit/2be3354c6c46215c7635eb1b76d80f1319403c68https://github.com/mariocasciaro/object-path/security/advisories/GHSA-cwx2-736x-mf6w
2020-10-19
Published