PT-2024-27073 · Almela · Obx

·

CVE-2024-36573

·

Published

2024-06-17

·

Updated

2024-08-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions almela obx versions prior to 0.0.4
Description The issue allows arbitrary code execution via the obx/build/index.js component, specifically through the reduce function at @almela/obx/build/index.js:470 and Object.set at obx/build/index.js:269. This is a Prototype Pollution issue.
Recommendations For versions prior to 0.0.4, update to version 0.0.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the obx/build/index.js component until a patch is available. Avoid using the vulnerable functions reduce and Object.set in the affected component until the issue is resolved.

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-36573
GHSA-JJ58-488V-4RGF

Affected Products

Obx