VDB
Sign up
MEDIUM5.9

GHSA-xcg2-9pp4-j82x

rollbar vulnerable to Prototype Pollution in merge()

Quick fix

GHSA-xcg2-9pp4-j82x — rollbar: upgrade to the fixed version with the command below.

npm install rollbar@2.26.5

Details

### Impact

Prototype pollution vulnerability in merge(). If application code calls `rollbar.configure()` with untrusted input, prototype pollution is possible.

### Patches

Fixed in 2.26.5 and 3.0.0-beta5.

### Workarounds

Ensure that values passed to `rollbar.configure()` do not contain untrusted input.

### References

Fixed in https://github.com/rollbar/rollbar.js/pull/1394 (2.26.x) and https://github.com/rollbar/rollbar.js/pull/1390 (3.x)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/rollbar
Introduced in: 0Fixed in: 2.26.5
Fixnpm install rollbar@2.26.5
npm/rollbar
Introduced in: 3.0.0-alpha1Fixed in: 3.0.0-beta5
Fixnpm install rollbar@3.0.0-beta5

References