2 ms·
The most common vulnerability that grants RCE has the attacker exploiting poorly designed deserialization code. Those are high impact but not too common since d
by mediumdeviation 5y ago
The most common vulnerability that grants RCE has the attacker exploiting poorly designed deserialization code. Those are high impact but not too common since deserialization is hopefully closely scrutinised.
There are other problems that naturally fall out of the fact that by default all objects, including those from JSON.parse, inherit the Object prototype though. For example -
- If you store user membership or permission as an object with some user controlled identifier (eg. a username) as key, then check if a user is permitted at all with `username in permissions`, a user can name themselves hasOwnProperty to bypass the check since it is part of the Object prototype
- If you deserialize some JSON then try to check membership with `o.hasOwnProperty(someKey)`, a malicious user can pass in JSON with hasOwnProperty as key. This will crash since hasOwnProperty is no longer a function on the object.
These are not necessarily common, but it’s annoying how easy it is for these to slip through. The object prototype in general is just a massive footgun