CVE-2024-57063
Published: 05 February 2025
Description
A prototype pollution in the lib function of php-date-formatter v1.3.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.
Security Summary
CVE-2024-57063 is a prototype pollution vulnerability in the lib function of the php-date-formatter library version 1.3.6. This issue enables attackers to cause a Denial of Service (DoS) condition by supplying a crafted payload. The vulnerability carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) and is classified under CWE-1321.
Remote attackers can exploit this vulnerability over the network without authentication, privileges, or user interaction, using low-complexity techniques. Successful exploitation results in high-impact disruption to availability, leading to a DoS, with no effects on confidentiality or integrity.
Mitigation details are available in the referenced advisory at https://gist.github.com/tariqhawis/dcb93b4788273c3ffb15f70dc45ca4e7.
Details
- CWE(s)