Prototype Pollution in vConsole v3.15.0 by Tencent
CVE-2023-30363

9.8CRITICAL

Key Information:

Vendor

Tencent

Status
Vendor
CVE Published:
26 April 2023

What is CVE-2023-30363?

vConsole v3.15.0 has been found to contain a prototype pollution vulnerability arising from improper handling of key and value resolution in the setOptions function within core.ts. This could potentially allow an attacker to manipulate the object's prototype, leading to unexpected behavior or security risks in applications using this version of vConsole.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.