Описание
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "proto" payload.
A flaw was found in nodejs-minimist, where it was tricked into adding or modifying properties of the Object.prototype using a "constructor" or "proto" payload. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Отчет
Red Hat Quay only includes minimist as a dependency of the test suites, and it not include it in the product. We may fix this issue in a future Red Hat Quay release.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Will not fix | ||
Red Hat OpenShift Container Platform 3.11 | kibana | Will not fix | ||
Red Hat OpenShift Container Platform 3.11 | openshift3/grafana | Will not fix | ||
Red Hat OpenShift Container Platform 4 | kibana | Will not fix | ||
Red Hat OpenShift Container Platform 4 | logging-kibana5-container | Will not fix | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-grafana | Will not fix | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-metering-hadoop | Will not fix | ||
Red Hat Openshift Container Storage 4 | ocs4/mcg-core-rhel8 | Not affected | ||
Red Hat Quay 3 | nodejs-minimist | Fix deferred | ||
Red Hat Software Collections | rh-nodejs10-nodejs-nodemon | Will not fix |
Показывать по
Дополнительная информация
Статус:
5.6 Medium
CVSS3
Связанные уязвимости
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
minimist before 1.2.2 could be tricked into adding or modifying proper ...
Уязвимость библиотеки minimist прикладного программного обеспечения Аврора Центр, связанная с неконтролируемым изменением атрибутов прототипа объекта, позволяющая нарушителю реализовать атаку типа «загрязнение прототипа»
5.6 Medium
CVSS3