VDB
Sign up
LOW

GHSA-r8c2-2qwq-94p6

rollbar vulnerable to prototype pollution

Quick fix

GHSA-r8c2-2qwq-94p6 — rollbar: upgrade to the fixed version with the command below.

npm install rollbar@2.26.5

Details

### Impact

Prototype pollution potential with the utility function `rollbar/src/utility`.`set()`. No impact when using the published public interface.

If application code directly imports `set` from `rollbar/src/utility` and then calls `set` with untrusted input in the second argument, it is vulnerable to prototype pollution.

POC:

```js const obj = {}; require("rollbar/src/utility").set(obj, "__proto__.polluted", "vulnerable"); console.log({}.polluted !== undefined ? '[POLLUTION_TRIGGERED]':''); ```

### Patches

Fixed in version 2.26.5 and 3.0.0-beta5.

### Workarounds

If application code directly imports `set` from `rollbar/src/utility`, ensure that the second argument does not receive untrusted input.

### References

https://github.com/rollbar/rollbar.js/issues/1333#issuecomment-3353720946

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/rollbar
Introduced in: 0Fixed in: 2.26.5
Fixnpm install rollbar@2.26.5
npm/rollbar
Introduced in: 3.0.0-alpha1Fixed in: 3.0.0-beta5
Fixnpm install rollbar@3.0.0-beta5

References