Описание
hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge' and 'applyToDefaults' functions, which allows a malicious user to modify the prototype of "Object" via proto, causing the addition or modification of an existing property that will exist on all objects.
Отчет
Red Hat Quay includes hoek as a dependency of protractor which is only used at build time. The vulnerable library is not used at runtime meaning this has a low impact on Red Hat Quay.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 8 | nodejs-hoek | Will not fix | ||
| Red Hat OpenShift Enterprise 3 | nodejs-hoek | Will not fix | ||
| Red Hat Software Collections | rh-nodejs4-nodejs-hoek | Will not fix | ||
| Red Hat Software Collections | rh-nodejs6-nodejs-hoek | Will not fix | ||
| Red Hat Virtualization 4 | ovirt-engine-api-explorer | Not affected | ||
| Red Hat Virtualization 4 | ovirt-engine-dashboard | Not affected | ||
| Red Hat Virtualization 4 | ovirt-engine-ui-extensions | Not affected | ||
| Red Hat Mobile Application Platform 4.6 | fh-system-dump-tool | Fixed | RHSA-2018:1263 | 30.04.2018 |
| Red Hat Mobile Application Platform 4.6 | fping | Fixed | RHSA-2018:1263 | 30.04.2018 |
| Red Hat Mobile Application Platform 4.6 | nagios | Fixed | RHSA-2018:1263 | 30.04.2018 |
Показывать по
Дополнительная информация
Статус:
EPSS
2.9 Low
CVSS3
Связанные уязвимости
hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge' and 'applyToDefaults' functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge' and 'applyToDefaults' functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Mo ...
EPSS
2.9 Low
CVSS3