Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-5258

Опубликовано: 10 мар. 2020
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Satellite 5dojoNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=1812404dojo: Prototype pollution in deepCopy method could result in code injection

EPSS

Процентиль: 83%
0.01992
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 7.7
ubuntu
почти 6 лет назад

In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2

CVSS3: 7.7
nvd
почти 6 лет назад

In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values. This has been patched in versions 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2

CVSS3: 7.7
debian
почти 6 лет назад

In affected versions of dojo (NPM package), the deepCopy method is vul ...

CVSS3: 7.7
github
почти 6 лет назад

Prototype pollution in dojo

CVSS3: 5.3
fstec
почти 6 лет назад

Уязвимость компонента Cluster: Packaging (dojo) системы управления базами данных Oracle MySQL Cluster, позволяющая нарушителю нарушить целостность данных

EPSS

Процентиль: 83%
0.01992
Низкий

3.7 Low

CVSS3