Improper Access Control Affecting pomelo package, versions <2.2.7
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.12% (47th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-POMELO-515804
- published 14 Nov 2019
- disclosed 14 Nov 2019
- credit Feng Xiao
Introduced: 14 Nov 2019
CVE-2019-18954 Open this link in a new tabHow to fix?
Upgrade pomelo
to version 2.2.7 or higher.
Overview
pomelo is a fast, scalable game server framework for NodeJS.
Affected versions of this package are vulnerable to Improper Access Control. A malicious user input can corrupt arbitrary methods and attributes in template/game-server/app/servers/connector/handler/entryHandler.js
because certain internal attributes can be overwritten via a conflicting name. Hence, a malicious attacker can manipulate internal attributes by adding additional attributes to user input.
References
CVSS Scores
version 3.1