首頁
» GitHub 公告
» GHSA-45rm-2893-5f49
描述
The package liquidjs before 10.0.0 is vulnerable to Information Exposure when ownPropertyOnly parameter is set to False, which results in leaking properties of a prototype. Workaround For versions 9.34.0 and higher, an option to disable this functionality is provided.
基本資訊
類型
reviewed
嚴重度
medium
GitHub 上的公告
開啟公告 ↗
儲存庫公告
—
原始碼
瀏覽原始碼 ↗
公開(公告)
2022-12-22 06:30:15 UTC
更新時間
2023-02-02 05:06:58 UTC
GitHub 審核
2022-12-22 20:03:15 UTC
NVD 公開
2022-12-22
EPSS Score
Score
Percentile
0.33%
55.54%
CVSS Scores
Base score
Version
Severity
Vector
5.3
3.1
—
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
點擊展開
攻擊向量 (AV:N)
可經網際網路或企業內可路由網段從遠端觸達,攻擊者不必在裝置旁邊。
攻擊複雜度 (AC:L)
前置條件清楚,成功路徑穩定,不必仰賴罕見競態或極端環境。
權限需求 (PR:N)
不必事先登入或提權,匿名工作階段也可能成為跳板。
使用者互動 (UI:N)
不必受害者點連結、放行巨集或安裝軟體,攻擊鏈可自動走完。
作用域 (S:U)
破壞局限在脆弱元件原本的安全權限與信任域之內。
機密性影響 (C:L)
可能外洩部分欄位或樣本資料,但難以形成「整批拖走」的局面。
完整性影響 (I:N)
對紀錄真實性與不可否認性的破壞可忽略。
可用性影響 (A:N)
不至於造成業務意義上的長時間停擺或災難性效能崩塌。
CWEs
CWE id
Name
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Affected packages (1)
Vulnerable version ranges and first patched releases as published by GitHub.
Ecosystem
Package
Vulnerable range
First patched
Vulnerable functions
npm
liquidjs
< 10.0.0
10.0.0
—
cvelogic
Threat Intelligence