@aedart/support is the support package for Ion, a monorepo for JavaScript/TypeScript packages. Prior to version `0.6.1`, there is a possible prototype pollution issue for the `MetadataRecord`, when merged with a base class' metadata object, in `meta` decorator from the `@aedart/support` package. The likelihood of exploitation is questionable, given that a class's metadata can only be set or altered when the class is decorated via `meta()`. Furthermore, object(s) of sensitive nature would have to be stored as metadata, before this can lead to a security impact. The issue has been patched in version `0.6.1`.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-1644 @aedart/support is the support package for Ion, a monorepo for JavaScript/TypeScript packages. Prior to version `0.6.1`, there is a possible prototype pollution issue for the `MetadataRecord`, when merged with a base class' metadata object, in `meta` decorator from the `@aedart/support` package. The likelihood of exploitation is questionable, given that a class's metadata can only be set or altered when the class is decorated via `meta()`. Furthermore, object(s) of sensitive nature would have to be stored as metadata, before this can lead to a security impact. The issue has been patched in version `0.6.1`.
Github GHSA Github GHSA GHSA-wwxh-74fx-33c6 Possible prototype pollution in metadata record, when using meta decorator
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 30 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-01-30T19:50:17.148Z

Reserved: 2023-04-18T16:13:15.882Z

Link: CVE-2023-30857

cve-icon Vulnrichment

Updated: 2024-08-02T14:37:15.508Z

cve-icon NVD

Status : Modified

Published: 2023-04-28T21:15:09.127

Modified: 2024-11-21T08:00:59.107

Link: CVE-2023-30857

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.