Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-28282

Опубликовано: 29 дек. 2020
Источник: redhat
CVSS3: 9.8

Описание

Prototype pollution vulnerability in 'getobject' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution.

A flaw was found in nodejs-getobject. The set() function does not check for the type of object before assigning value to the property allowing an attacker to create a non-existent property or allow the manipulation of the property which could lead to a denial of service or a remote code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Отчет

In OpenShift ServiceMesh (OSSM) the affected components are behind OpenShift OAuth authentication. This restricts access to the vulnerable nodejs-getobject library to authenticated users only, therefore the impact is Low. OpenShift ServiceMesh (OSSM) 1.1 is out of support scope for Moderate and Low impact vulnerabilities, hence is marked Out Of Support Scope.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 1servicemesh-grafanaNot affected
OpenShift Service Mesh 2.0servicemesh-grafanaNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-915
https://bugzilla.redhat.com/show_bug.cgi?id=1912463nodejs-getobject: Prototype pollution could result in DoS and RCE

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 5 лет назад

Prototype pollution vulnerability in 'getobject' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution.

CVSS3: 9.8
nvd
около 5 лет назад

Prototype pollution vulnerability in 'getobject' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution.

CVSS3: 9.8
debian
около 5 лет назад

Prototype pollution vulnerability in 'getobject' version 0.1.0 allows ...

CVSS3: 9.8
github
больше 4 лет назад

Prototype pollution in getobject

9.8 Critical

CVSS3