cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot be resolved, the existing target member is detached and deleted before the operation is fully validated, so the target document is mutated while cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() returns a failure status. An attacker who can supply the patch document can destroy addressable members of the target document even though the API reports that the patch failed, defeating the all-or-nothing behavior callers rely on to reject bad patches.
Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback module) allows an attacker to make a victim's browser complete an authorization flow the victim never initiated. This vulnerability is associated with program file lib/oidcc/plug/authorization_callback.ex and program routine Oidcc.Plug.AuthorizationCallback.call/2. A callback request that carries no Oidcc.Plug.Authorize session is processed with every security check disabled rather than being rejected. call/2 substitutes permissive defaults for the absent session, and each downstream check treats its value as nothing to compare and returns :ok, so the nonce, state, PKCE, peer IP and user agent checks are all skipped. A separate clause of check_state/2 also accepts a state-less request when a verifier is present. An attacker obtains an authorization code for their own provider account, then induces the victim to visit the callback endpoint with that code and no state parameter. The application signs the victim in as the attacker, so the victim's subsequent actions occur in the attacker's account where the attacker can read them. Applications reusing one callback for both signing in and linking a provider account are further exposed to account takeover, the attacker's account becoming linked to the victim's. The permissive fallback serves no conforming flow. Third-party-initiated login reaches a relying party at a separate login initiation endpoint and causes it to send a fresh authentication request, and this library implements no such endpoint. Oidcc.Plug.Authorize always sends a state parameter, which an authorization server must echo, so no legitimate callback lacks one. This issue affects oidcc_plug: from 0.2.0-beta.1 before 0.5.0.
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into surgical, invisible modification of all JSON API responses — including privilege escalation, balance manipulation, and authorization bypass. The default transformResponse function at lib/defaults/index.js:124 calls JSON.parse(data, this.parseReviver), where this is the merged config object. Because parseReviver is not present in Axios defaults, not validated by assertOptions, and not subject to any constraints, a polluted Object.prototype.parseReviver function is called for every key-value pair in every JSON response, allowing the attacker to selectively modify individual values while leaving the rest of the response intact. This vulnerability is fixed in 1.15.2.
| Version | Type | Source | Base | Exp | Imp |
|---|---|---|---|---|---|
| 3.1 | Primary | NVD | 9.1 | 3.9 | 5.2 |
| 3.1 | Primary | cve.org | 7.4 | — | — |
| 3.1 | Primary | cve.org | 7.4 | — | — |
| 3.1 | Primary | cve.org | 7.4 | — | — |
| 3.1 | Primary | cve.org | 7.4 | — | — |
| 3.1 | Primary | cve.org | 7.4 | — | — |
| 3.1 | Primary | cve.org | 7.4 | — | — |
| 3.1 | Primary | cve.org | 7.4 | — | — |
| 3.1 | Primary | cve.org | 7.4 | — | — |
| 3.1 | Primary | cve.org | 7.4 | — | — |
| 3.1 | Primary | cve.org | 7.4 | — | — |
| 3.1 | Primary | cve.org | 7.4 | — | — |
| 3.1 | Primary | cve.org | 7.4 | — | — |
| 3.1 | Primary | cve.org | 7.4 | — | — |
| 3.1 | Primary | cve.org | 7.4 | — | — |
| 3.1 | Primary | cve.org | 7.4 | — | — |
| 3.1 | Primary | cve.org | 7.4 | — | — |
| 3.1 | Primary | cve.org | 7.4 | — | — |
| 3.1 | Primary | cve.org | 7.4 | — | — |
| 3.1 | Primary | cve.org | 7.4 | — | — |
| 3.1 | Primary | cve.org | 6.5 | — | — |
| 3.1 | Primary | cve.org | 6.5 | — | — |
| 3.1 | Primary | cve.org | 6.5 | — | — |
| 3.1 | Primary | cve.org | 6.5 | — | — |
| 3.1 | Primary | cve.org | 6.5 | — | — |
| 3.1 | Primary | cve.org | 6.5 | — | — |
| 3.1 | Primary | cve.org | 6.5 | — | — |
| 3.1 | Primary | cve.org | 6.5 | — | — |
| 3.1 | Primary | cve.org | 6.5 | — | — |
| 3.1 | Primary | cve.org | 6.5 | — | — |
| 3.1 | Primary | cve.org | 6.5 | — | — |
| 3.1 | Primary | cve.org | 6.5 | — | — |
| 3.1 | Primary | cve.org | 6.5 | — | — |
| 3.1 | Primary | cve.org | 6.5 | — | — |
| 3.1 | Primary | cve.org | 6.5 | — | — |
| 3.1 | Primary | cve.org | 6.5 | — | — |
| 3.1 | Primary | cve.org | 6.5 | — | — |
| 3.1 | Primary | cve.org | 6.5 | — | — |
| 3.1 | Primary | cve.org | 6.5 | — | — |
| 3.1 | Primary | cve.org | 6.5 | — | — |
| 3.1 | Primary | cve.org | 6.5 | — | — |
| 3.1 | Secondary | NVD | 7.4 | 2.2 | 5.2 |
| 3.1 | Secondary | NVD | 6.5 | 2.2 | 4.2 |
| 3.1 | Secondary | ENISA EUVD | 6.5 | — | — |
| 3.1 | Secondary | GHSA | 6.5 | — | — |