CRITICAL9.8
GHSA-v9p9-535w-4285
Prototype Pollution in litespeed.js and appwrite/server-ce
Quick fix
GHSA-v9p9-535w-4285 — litespeed.js: upgrade to the fixed version with the command below.
npm install litespeed.js@0.3.12Details
This affects the package litespeed.js before 0.3.12; the package appwrite/server-ce from 0.12.0 and before 0.12.2, before 0.11.1. When parsing the query string in the getJsonFromUrl function, the key that is set in the result object is not properly sanitized leading to a Prototype Pollution vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/appwrite/server-ce
Introduced in:
0.12.0Fixed in: 0.12.2Fix
composer require appwrite/server-ce:^0.12.2Packagist/appwrite/server-ce
Introduced in:
0Fixed in: 0.11.1Fix
composer require appwrite/server-ce:^0.11.1References
- https://nvd.nist.gov/vuln/detail/CVE-2021-23682[ADVISORY]
- https://github.com/appwrite/appwrite/pull/2778[WEB]
- https://github.com/litespeed-js/litespeed.js/pull/18[WEB]
- https://github.com/appwrite/appwrite/releases/tag/0.11.1[WEB]
- https://github.com/appwrite/appwrite/releases/tag/0.12.2[WEB]
- https://snyk.io/vuln/SNYK-JS-LITESPEEDJS-2359250[WEB]
- https://snyk.io/vuln/SNYK-PHP-APPWRITESERVERCE-2401820[WEB]