This month?s developer update is jam-packed with exciting news, helpful articles, and useful code, including a new Terraform Provider release and much more.
Summary
A prototype pollution vulnerability in Blitz.js can allow attacker to remotely execute code on Node.js servers, according to a report from researchers at Sonar.
Threat Type
Vulnerability
Overview
A prototype pollution vulnerability (CVE-2022-23631) in Blitz.js could allow for remote code execution in an unauthenticated state. Should the Blitz.js-based application implement at least one RPC call makes the application vulnerable. Prototype pollution occurs when an attack can gain control over a proto