Application Security von Cloudflare
WAF erkennt Prototype Pollution
Die WAF-Releases enthalten neue Erkennungen für Prototype Pollution über die Angriffsvektoren URI, Body und Header/Form.
This week’s release introduces new detections for Prototype Pollution across three common vectors: URI, Body, and Header/Form.
Key Findings
- These attacks can affect both API and web applications by altering normal behavior or bypassing security controls.
Impact
Exploitation may allow attackers to change internal logic or cause unexpected behavior in applications using JavaScript or Node.js frameworks. Developers should sanitize input keys and avoid merging untrusted data structures.
Ruleset
Rule ID
Legacy Rule ID
Description
Previous Action
New Action
Comments
Cloudflare Managed Ruleset
...606285e6
N/A
Generic Rules - Prototype Pollution - URI
Log
Disabled
This is a new detection
Cloudflare Managed Ruleset
...4f59ff26
N/A
Generic Rules - Prototype Pollution - Body
Log
Disabled
This is a new detection
Cloudflare Managed Ruleset
...7efbeb39
N/A
Generic Rules - Prototype Pollution - Header - Form
Log
Disabled
This is a new detection