QID 981616
QID 981616: Nodejs (npm) Security Update for pomelo (GHSA-4x6v-rwh4-55jw)
Pomelo v2.2.5 allows external control of critical state data. A malicious user input can corrupt arbitrary methods and attributes in template/game-server/app/servers/connector/handler/entryHandler.js because certain internal attributes can be overwritten via a conflicting name. Hence, a malicious attacker can manipulate internal attributes by adding additional attributes to user input.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-4x6v-rwh4-55jw for updates pertaining to this vulnerability.
Vendor References
- GHSA-4x6v-rwh4-55jw -
github.com/advisories/GHSA-4x6v-rwh4-55jw
CVEs related to QID 981616
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4x6v-rwh4-55jw | pomelo |
|