Lodash¿âÔÐÍÎÛȾ©¶´£¨CVE-2019-10744£©
Ðû²¼Ê±¼ä 2019-07-12
Åä¾°ÃèÊö
©¶´Áбí
©¶´Æ·¼¶£º ¸ßΣ
CVSSÆÀ·Ö£º 7.3
Ó°Ï췶Χ£º 4.17.11֮ǰµÄËùÓа汾
©¶´ÏêÇé
ͨ¹ý½á¹¹º¯ÊýÖØÔصķ½Ê½£¬Lodash ¿âÖеĺ¯Êý defaultsDeep ºÜÓпÉÄܻᱻÆÛÆÌí¼Ó»òÐÞ¸Ä Object.prototype µÄÊôÐÔ£¬×îÖÕ¿ÉÄܵ¼Ö Web Ó¦Ó÷¨Ê½±ÀÀ£»ò¸Ä±äÆäÐÐΪ£¬¾ßÌåÈ¡¾öÓÚÊÜÓ°ÏìµÄÓÃÀý¡£
Pony by Snyk
ÔÐÍÎÛȾÊÇÒ»¸öÓ°Ïì JavaScript µÄ©¶´¡£ÔÐÍÎÛȾÊÇÖ¸½«ÊôÐÔ×¢ÈëÏÖÓÐ JavaScript ÓïÑԽṹÔÐÍ£¨È繤¾ß£©µÄÄÜÁ¦¡£JavaScript ÔÊÐíËùÓй¤¾ßÊôÐÔ±»¸ü¸Ä£¬ÀýÈçÈç_proto_£¬constructorºÍprototype¡£¹¥»÷Õßͨ¹ý×¢ÈëÆäËüÖµÀ´ÀûÓÃÕâЩÊôÐÔÀ´ÁýÕÖ»òÎÛȾ»ù´¡¹¤¾ßµÄ JavaScript Ó¦Ó÷¨Ê½¹¤¾ßÔÐÍ¡£ÕâÑùºÜ¿ÉÄÜ»áÓ°ÏìÓ¦Ó÷¨Ê½Í¨¹ýÔÐÍÁ´´¦Öà JavaScript ¹¤¾ßµÄ¹ý³Ì£¬´Ó¶øµ¼Ö¾ܾø·þÎñ»òÔ¶³Ì´úÂëÖ´ÐС£
ÔÐÍÎÛȾµÄÁ½ÖÖÖ÷Òª·½Ê½£º
²»Äþ¾²µÄObjectµÝ¹éºÏ²¢
°´Â·¾¶½ç˵ÊôÐÔ
²»Äþ¾²µÄ¹¤¾ßµÝ¹éºÏ²¢
Ò×Êܹ¥»÷µÄµÝ¹éºÏ²¢º¯ÊýµÄÂß¼×ñÑÒÔϸ߼¶Ä£ÐÍ£º

È»ºó¹¥»÷ÕßÔÚ Object ÔÐÍÉϸ´ÖÆÊôÐÔ¡£
¿Ë¡²Ù×÷ÊÇÒ»¸öÌØÊâµÄ²»Äþ¾²µÝ¹éºÏ²¢×ÓÀ࣬Ëü·¢ÉúÔÚ¶Ô¿Õ¹¤¾ß½øÐеݹéºÏ²¢Ê±£ºmerge({},source)¡£
lodash ºÍ Hoek ÊÇÒ×ÊܵݹéºÏ²¢¹¥»÷Ó°Ïì¡£
°´Â·¾¶½ç˵ÊôÐÔ
Èç¹û¹¥»÷Õß¿ÉÒÔ¿ØÖÆ¡°Â·¾¶¡±µÄÖµ£¬Ôò¿ÉÒÔ½«´ËÖµÉèÖÃΪ_proto_.myValue¡£
·À·¶´ëÊ©
¶³½á Object.prototype £¬Ê¹ÔÐͲ»ÄÜÀ©³äÊôÐÔ
½¨Á¢ JSON schema
¹æ±Ü²»Äþ¾²µÄµÝ¹éÐԺϲ¢º¯Êý
ʹÓÃÎÞÔÐ͹¤¾ß£¬´òÆÆÔÐÍÁ´²¢·ÀÖ¹ÎÛȾ¡£
½ÓÄÉÐ嵀 Map Êý¾ÝÀàÐÍ£¬È¡´ú Object ÀàÐÍ
ËäÈ»ÔÐÍÎÛȾ©¶´Ó°Ïì·Ç³£ÑÏÖØ£¬µ«Êǹ¥»÷ÕßÏëÒªÀûÓÃËü²¢Ã»ÓÐÄÇôÈÝÒ×£¬ËûÃÇÐèÒªÉîÈëÁ˽âÿ¸ö Web Ó¦ÓõÄÊÂÇéÔÀí¡£
ÐÞ¸´½¨Òé
²Î¿¼Á´½Ó
https://snyk.io/vuln/SNYK-JS-LODASH-450202
https://snyk.io/blog/snyk-research-team-discovers-severe-prototype-pollution-security-vulnerabilities-affecting-all-versions-of-lodash/
https://snyk-rules-pre-repository.s3.amazonaws.com/snapshots/master/patches/npm/lodash/20190702/lodash_20190702_0_0_1f8ea07746963a535385a5befc19fa687a627d2b.patch