VDB
Sign up
LOW3.7

GHSA-gg4h-3hg2-grpc

joi: object().rename() with a template target can set the validated object's prototype

Quick fix

GHSA-gg4h-3hg2-grpc — joi: upgrade to the fixed version with the command below.

npm install joi@17.13.5

Details

### Impact

Applications are affected only if a schema renames keys with a regular-expression source and a `Joi.expression()` / `Joi.x()` target that interpolates the pattern's own match data, combined with `{ multiple: true }`, for example `.rename(/^x-(.+)$/, Joi.x('{#1}'), { multiple: true })`. Because the target is rendered from the matched input key, an attacker who controls input keys can send `x-__proto__` with an object value and make the rename target render as `__proto__`, which sets the prototype of the object joi returns instead of creating a key on it. The global `Object.prototype` is not modified, so the effect is confined to the object returned by that one `validate()` call.

Schemas using a static string rename target are not affected, and neither are schemas left on the default `{ multiple: false }`.

### Patches

Versions 17.13.5 and 18.2.4 have been released to address the issue.

### Workarounds

1. Replace the template rename target with a static string target. 2. Keep the template but make the capture unable to produce `__proto__`, using a negative lookahead: `.rename(/^x-(?!__proto__$)(.+)$/, Joi.x('{#1}'), { multiple: true })` 3. Drop { multiple: true } from the rename, which stops the rename before the assignment.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/joi
Introduced in: 16.0.0Fixed in: 17.13.5
Fixnpm install joi@17.13.5
npm/joi
Introduced in: 18.0.0Fixed in: 18.2.4
Fixnpm install joi@18.2.4

References