3 ms·
Fair point, I should have cited that. From snyk: https://www.google.com/search?hl=en&q=prototype%20pollution%20site%3Asnyk.io https://www.google.com/search?hl=e
by tmcw 6y ago
Fair point, I should have cited that. From snyk: https://www.google.com/search?hl=en&q=prototype%20pollution%20site%3Asnyk.io https://www.google.com/search?hl=en&q=prototype%20pollution%...
You'll see prototype pollution CVEs in such libraries as jQuery, Lodash, handlebars, ajv (and transitively, request). A pretty good set of modules that are heavily used.
Scroll through the latest vunerabilities in the database and you'll see prototype pollution popping up very reliably https://snyk.io/vuln?type=npm https://snyk.io/vuln?type=npm
- rbg246 6y agoMay I ask for clarification? Is my understanding correct in saying that this is a peculiarly JavaScript issue because you can overwrite language constructs on the object prototype? Whereas in other languages I can't affect the language core constructs?
- tmcw 6y agoMost languages have one kind of "object" used for data and another kind used for instances of classes associated with OO programming. JavaScript traditionally uses one kind for both (traditionally, in that there is now an alternative, Map, but it's underused https://macwright.com/2017/03/13/maps-not-strictly-better.html https://macwright.com/2017/03/13/maps-not-strictly-better.ht... ) In other languages, the data kind of object - dicts in python, hashes in ruby - allows you to associate any key with any value. In JavaScript, the hybrid kind of object that's used for both, allows you to associate keys with values, but has some keys that are special, like __proto__, that override language constructs and cause chaos and vulnerabilities.