Описание
lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via proto, causing the addition or modification of an existing property that will exist on all objects.
Отчет
Red Hat CloudForms version 4.7 does not ship component lodash, so isn't affected by this flaw. Red Hat Virtualization 4.2 EUS includes a vulnerable version of lodash as part of the ovirt-engine-dashboard package. This package has been removed from Red Hat Virtualization 4.3.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| CloudForms Management Engine 5 | lodash-rails | Will not fix | ||
| Red Hat Mobile Application Platform 4 | nodejs-lodash | Not affected | ||
| Red Hat OpenShift Enterprise 3 | nodejs-lodash | Will not fix | ||
| Red Hat Virtualization 4 | ovirt-engine-api-explorer | Not affected | ||
| Red Hat Virtualization 4 | ovirt-engine-dashboard | Out of support scope | ||
| Red Hat Virtualization 4 | ovirt-engine-ui-extensions | Not affected | ||
| Red Hat Quay 3 | quay/quay-rhel8 | Fixed | RHSA-2021:3917 | 19.10.2021 |
Показывать по
Дополнительная информация
Статус:
2.9 Low
CVSS3
Связанные уязвимости
lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
lodash node module before 4.17.5 suffers from a Modification of Assume ...
2.9 Low
CVSS3