Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

Jump to content

Prototype pollution

From Wikipedia, the free encyclopedia

Prototype pollution is a class of vulnerabilities in prototype-based languages such as JavaScript runtimes that allows attackers to overwrite arbitrary properties in an object's root prototype.[1][2][3][4][5][6] In a prototype pollution attack, attackers inject properties into existing JavaScript construct prototypes with unsafe merges. Prototype pollution can affect client-side and server-side runtimes. Using prototype pollution to modify properties called by gadgets could lead to Denial of Service (DoS) attacks, code execution, or privilege escalation.[7]

References

[edit]
  1. ↑ Li, Song; Kang, Mingqing; Hou, Jianwei; Cao, Yinzhi (2021-08-18). "Detecting Node.js prototype pollution vulnerabilities via object lookup analysis". Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering. ESEC/FSE 2021. New York, NY, USA: Association for Computing Machinery. pp. 268–279. doi:10.1145/3468264.3468542. ISBN 978-1-4503-8562-6.
  2. ↑ Kang, Zifeng; Li, Song; Cao, Yinzhi (2022). "Probe the Proto: Measuring Client-Side Prototype Pollution Vulnerabilities of One Million Real-world Websites". Proceedings 2022 Network and Distributed System Security Symposium. Reston, VA: Internet Society. doi:10.14722/ndss.2022.24308. ISBN 978-1-891562-74-7.{{cite journal}}: CS1 maint: periodical has ISBN (link)
  3. ↑ Shcherbakov, Mikhail; Balliu, Musard; Staicu, Cristian-Alexandru (2023). "Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js". SEC '23: Proceedings of the 32nd USENIX Conference on Security Symposium: 5521–5538. arXiv:2207.11171. ISBN 978-1-939133-37-3.{{cite journal}}: CS1 maint: periodical has ISBN (link)
  4. ↑ Cornelissen, Eric; Shcherbakov, Mikhail; Balliu, Musard (2024). "{GHunter}: Universal Prototype Pollution Gadgets in {JavaScript} Runtimes". USENIX Security: 3693–3710. ISBN 978-1-939133-44-1.{{cite journal}}: CS1 maint: periodical has ISBN (link)
  5. ↑ Hakim, Ismail Abdurrahman; Widyawan; Mustika, I Wayan; Prasetyo, Eko (2023-12-01). "A Multivocal Literature Review on Prototype Pollution Vulnerability". 2023 International Conference on Information Technology and Computing (ICITCOM). IEEE. pp. 375–379. doi:10.1109/ICITCOM60176.2023.10442205. ISBN 979-8-3503-5963-3.
  6. ↑ Kim, Hee Yeon; Kim, Ji Hoon; Oh, Ho Kyun; Lee, Beom Jin; Mun, Si Woo; Shin, Jeong Hoon; Kim, Kyounggon (2022-02-01). "DAPP: automatic detection and analysis of prototype pollution vulnerability in Node.js modules". International Journal of Information Security. 21 (1): 1–23. doi:10.1007/s10207-020-00537-0. ISSN 1615-5270.
  7. ↑ Shcherbakov, Mikhail; Balliu, Musard (2023). USENIX Association (ed.). Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js (PDF). Berkeley, CA: USENIX Association. ISBN 978-1-939133-37-3.
[edit]