Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-3719

Опубликовано: 25 апр. 2018
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via proto, causing the addition or modification of an existing property that will exist on all objects.

Отчет

In Red Hat OpenShift Logging the openshift-logging/kibana6-rhel8 container bundles many nodejs packages as a build time dependencies, including the mixin-deep package. The vulnerable code is not used hence the impact to OpenShift Logging by this vulnerability is Low.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-471
https://bugzilla.redhat.com/show_bug.cgi?id=1576648nodejs-mixin-deep: Prototype pollution via merging functions

EPSS

Процентиль: 70%
0.00639
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

CVSS3: 8.8
nvd
больше 7 лет назад

mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

CVSS3: 8.8
debian
больше 7 лет назад

mixin-deep node module before 1.3.1 suffers from a Modification of Ass ...

CVSS3: 8.8
github
больше 7 лет назад

Prototype Pollution in mixin-deep

EPSS

Процентиль: 70%
0.00639
Низкий

3.3 Low

CVSS3