Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10747

Опубликовано: 20 июн. 2019
Источник: redhat
CVSS3: 4.2

Описание

set-value is vulnerable to Prototype Pollution in versions lower than 3.0.1. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using any of the constructor, prototype and proto payloads.

A flaw was found in nodejs-set-value. The function mixin-deep can be tricked into adding or modifying properties of Object.prototype using any of the constructor, prototype, or proto payloads. The highest threat from this vulnerability is to data confidentiality and integrity.

Отчет

While OpenShift Container Platform (OCP) contains the affected nodejs-set-value code, it's added as a dependency of Kibana 5. Similar issue about prototype pollution [1] have been fixed, but no known attack vector was found, so we're rating this issue as Low for OCP. In Red Hat Software Collections and Red Hat Enterprise Linux 8, nodejs-set-value is bundled into nodejs-nodemon, and is not meant to be accessed outside of that package. Within nodemon, this flaw is rated with a Low severity. OpenShift distributed tracing bundles vulnerable version of Nodejs set-value package, however the components are protected by OpenShift OAuth, hence the impact by this vulnerability is reduced to LOW. [1] CVE-2019-10744 https://www.elastic.co/community/security

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8nodejs:10/nodejs-nodemonFix deferred
Red Hat OpenShift Container Platform 3.11kibanaWill not fix
Red Hat OpenShift Container Platform 4kibanaWill not fix
Red Hat OpenShift distributed tracing 2rhosdt/jaeger-all-in-one-rhel8Fix deferred
Red Hat Quay 3nodejs-set-valueNot affected
Red Hat Software Collectionsrh-nodejs10-nodejs-nodemonFix deferred
Red Hat Enterprise Linux 8nodejsFixedRHSA-2021:054916.02.2021
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-nodejs12-nodejsFixedRHSA-2021:048511.02.2021
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-nodejs12-nodejs-nodemonFixedRHSA-2021:048511.02.2021
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSrh-nodejs12-nodejsFixedRHSA-2021:048511.02.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-471
https://bugzilla.redhat.com/show_bug.cgi?id=1795479nodejs-set-value: prototype pollution in function set-value

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 6 лет назад

set-value is vulnerable to Prototype Pollution in versions lower than 3.0.1. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using any of the constructor, prototype and _proto_ payloads.

CVSS3: 9.8
nvd
почти 6 лет назад

set-value is vulnerable to Prototype Pollution in versions lower than 3.0.1. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using any of the constructor, prototype and _proto_ payloads.

CVSS3: 9.8
debian
почти 6 лет назад

set-value is vulnerable to Prototype Pollution in versions lower than ...

CVSS3: 9.8
github
почти 6 лет назад

Prototype Pollution in set-value

CVSS3: 9.8
fstec
около 4 лет назад

Уязвимость функции set библиотеки set-value прикладного программного обеспечения Аврора Центр, связанная с неконтролируемым изменением атрибутов прототипа объекта, позволяющая нарушителю реализовать атаку типа «загрязнение прототипа»

4.2 Medium

CVSS3