3 ms·
This article is not very good in convincing that prototype pollution is a problem. There was a write up about the kibana rce that really shows it's a problem:
by furstenheim 5y ago
This article is not very good in convincing that prototype pollution is a problem.
There was a write up about the kibana rce that really shows it's a problem:
https://research.securitum.com/prototype-pollution-rce-kibana-cve-2019-7609/ https://research.securitum.com/prototype-pollution-rce-kiban...
- ble 5y agoThanks for the link, this is a much clearer example of how prototype pollution can be an important vector. As another commenter noted, if one can directly inject literal JS code that writes to __proto__, you've already got RCE. The case where prototype pollution happens without arbitrary RCE looks like: - User input can set arbitrary fields of an object and its properties, allowing the user to add or alter a field on a `__proto__` that references a widely-shared prototype; - The existence or value of that field non-locally affects other code which assumes that the prototype is not under user control.