CVE-2023-45827 is a critical Prototype Pollution vulnerability affecting the dot-diver utility library, specifically within its setByPath function in versions prior to 1.0.2. This flaw allows for remote code execution (RCE) due to the manipulation of object prototypes. The vulnerability carries a CVSS score of 9.8 (CRITICAL) with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating it can be exploited over the network with low attack complexity, requiring no privileges or user interaction, and leading to complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community attention with 11 mentions, suggesting awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.2CPE matchmatch criteria | cpe:2.3:a:clickbar:dot-diver:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.