Rewterz Threat Alert – BlueBravo, A Russian APT, Employs GraphicalProton Backdoor to Target Diplomatic Entities – Active IOCs
August 1, 2023Rewterz Threat Advisory – Multiple Mozilla Firefox Vulnerabilities
August 2, 2023Rewterz Threat Alert – BlueBravo, A Russian APT, Employs GraphicalProton Backdoor to Target Diplomatic Entities – Active IOCs
August 1, 2023Rewterz Threat Advisory – Multiple Mozilla Firefox Vulnerabilities
August 2, 2023Severity
High
Analysis Summary
CVE-2023-26139
Node.js underscore-keypath module is vulnerable to a denial of service, caused by a prototype pollution in the setProperty() function. By sending a specially crafted request using the name parameter, a remote attacker could exploit this vulnerability to cause a denial of service.
Impact
- Denial of Service
Indicators Of Compromise
CVE
- CVE-2023-26139
Affected Vendors
Node.js
Affected Products
- Node.js underscore-keypath 0.0.11
- Node.js underscore-keypath 0.9.3
Remediation
Refer to NPM Website for patch, upgrade or suggested workaround information.