Lodash¿âÔÐÍÎÛȾÎó²î£¨CVE-2019-10744£©
Ðû²¼Ê±¼ä 2019-07-12
Åä¾°ÐÎò
Îó²îÁбí
Îó²îÆ·¼¶£º ¸ßΣ
CVSSÆÀ·Ö£º 7.3
Ó°Ïì¹æÄ££º 4.17.11֮ǰµÄËùÓа汾
Îó²îÏêÇé
ͨ¹ý½á¹¹º¯ÊýÖØÔØµÄ·½·¨£¬£¬£¬£¬Lodash ¿âÖеĺ¯Êý defaultsDeep ºÜÓпÉÄܻᱻÓÕÆÌí¼Ó»òÐÞ¸Ä Object.prototype µÄÊôÐÔ£¬£¬£¬£¬×îÖÕ¿ÉÄܵ¼Ö Web Ó¦ÓóÌÐò±ÀÀ£»£»£»ò¸Ä±äÆäÐÐΪ£¬£¬£¬£¬Ïêϸȡ¾öÓÚÊÜÓ°ÏìµÄÓÃÀý¡£¡£¡£¡£¡£
Pony by Snyk
ÔÐÍÎÛȾÊÇÒ»¸öÓ°Ïì JavaScript µÄÎó²î¡£¡£¡£¡£¡£ÔÐÍÎÛȾÊÇÖ¸½«ÊôÐÔ×¢ÈëÏÖÓÐ JavaScript ÓïÑԽṹÔÐÍ£¨È繤¾ß£©µÄÄÜÁ¦¡£¡£¡£¡£¡£JavaScript ÔÊÐíËùÓй¤¾ßÊôÐÔ±»¸ü¸Ä£¬£¬£¬£¬ÀýÈçÈç_proto_£¬£¬£¬£¬constructorºÍprototype¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ý×¢ÈëÆäËüÖµÀ´Ê¹ÓÃÕâЩÊôÐÔÀ´ÁýÕÖ»òÎÛȾ»ù´¡¹¤¾ßµÄ JavaScript Ó¦ÓóÌÐò¹¤¾ßÔÐÍ¡£¡£¡£¡£¡£ÕâÑùºÜ¿ÉÄÜ»áÓ°ÏìÓ¦ÓóÌÐòͨ¹ýÔÐÍÁ´´¦Öóͷ£ JavaScript ¹¤¾ßµÄÀú³Ì£¬£¬£¬£¬´Ó¶øµ¼Ö¾ܾøÐ§ÀÍ»òÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£
ÔÐÍÎÛȾµÄÁ½ÖÖÖ÷Òª·½·¨£º
²»Çå¾²µÄObjectµÝ¹éºÏ²¢
°´Â·¾¶½ç˵ÊôÐÔ
²»Çå¾²µÄ¹¤¾ßµÝ¹éºÏ²¢
Ò×Êܹ¥»÷µÄµÝ¹éºÏ²¢º¯ÊýµÄÂß¼×ñÕÕÒÔϸ߼¶Ä£×Ó£º

È»ºó¹¥»÷ÕßÔÚ Object ÔÐÍÉϸ´ÖÆÊôÐÔ¡£¡£¡£¡£¡£
¿Ë¡²Ù×÷ÊÇÒ»¸öÌØÊâµÄ²»Çå¾²µÝ¹éºÏ²¢×ÓÀ࣬£¬£¬£¬Ëü±¬·¢ÔÚ¶Ô¿Õ¹¤¾ß¾ÙÐеݹéºÏ²¢Ê±£ºmerge({},source)¡£¡£¡£¡£¡£
lodash ºÍ Hoek ÊÇÒ×ÊܵݹéºÏ²¢¹¥»÷Ó°Ïì¡£¡£¡£¡£¡£
°´Â·¾¶½ç˵ÊôÐÔ
ÈôÊǹ¥»÷Õß¿ÉÒÔ¿ØÖÆ¡°Â·¾¶¡±µÄÖµ£¬£¬£¬£¬Ôò¿ÉÒÔ½«´ËÖµÉèÖÃΪ_proto_.myValue¡£¡£¡£¡£¡£
·À·¶´ëÊ©
¶³½á Object.prototype £¬£¬£¬£¬Ê¹ÔÐͲ»¿ÉÀ©³äÊôÐÔ
½¨Éè JSON schema
¹æ±Ü²»Çå¾²µÄµÝ¹éÐԺϲ¢º¯Êý
ʹÓÃÎÞÔÐ͹¤¾ß£¬£¬£¬£¬Í»ÆÆÔÐÍÁ´²¢±ÜÃâÎÛȾ¡£¡£¡£¡£¡£
½ÓÄÉÐ嵀 Map Êý¾ÝÀàÐÍ£¬£¬£¬£¬È¡´ú Object ÀàÐÍ
ËäÈ»ÔÐÍÎÛȾÎó²îÓ°ÏìºÜÊÇÑÏÖØ£¬£¬£¬£¬¿ÉÊǹ¥»÷ÕßÏëҪʹÓÃËü²¢Ã»ÓÐÄÇôÈÝÒ×£¬£¬£¬£¬ËûÃÇÐèÒªÉîÈëÏàʶÿ¸ö Web Ó¦ÓõÄÊÂÇéÔÀí¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
²Î¿¼Á´½Ó
https://snyk.io/vuln/SNYK-JS-LODASH-450202
https://snyk.io/blog/snyk-research-team-discovers-severe-prototype-pollution-security-vulnerabilities-affecting-all-versions-of-lodash/
https://snyk-rules-pre-repository.s3.amazonaws.com/snapshots/master/patches/npm/lodash/20190702/lodash_20190702_0_0_1f8ea07746963a535385a5befc19fa687a627d2b.patch