漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
primefaces primereact API ObjectUtils.mutateFieldData prototype pollution
Vulnerability Description
A weakness has been identified in primefaces primereact up to 10.9.8. This issue affects the function ObjectUtils.mutateFieldData of the component API. This manipulation of the argument Field causes improperly controlled modification of object prototype attributes. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet. This vulnerability only affects products that are no longer supported by the maintainer.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
CWE-1321
Vulnerability Title
Primetek primefaces 输入验证错误漏洞
Vulnerability Description
Primetek primefaces是Primetek公司开源的一款JavaServerFaces组件库。 Primetek primefaces存在安全漏洞,该漏洞源于API组件中ObjectUtils.mutateFieldData函数对参数Field的操作导致对象原型属性控制不当,可能导致远程攻击。
CVSS Information
N/A
Vulnerability Type
N/A