Описание
The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.
A flaw was found in nodejs-y18n. There is a prototype pollution vulnerability in y18n's locale functionality. If an attacker is able to provide untrusted input via locale, they may be able to cause denial of service or in rare circumstances, impact to data integrity or confidentiality.
Отчет
In OpenShift Container Platform (OCP), OpenShift ServiceMesh (OSSM) and OpenShift distributed tracing the affected components are behind OpenShift OAuth authentication. This restricts access to the vulnerable nodejs-y18n library to authenticated users only, therefore the impact is Low. In Red Hat OpenShift Container Storage 4 the noobaa-core container includes the affected version of y18n as a dependency of yargs. However, no unsafe usage found where the module accepts untrusted input and hence this issue has been rated as having a security impact of Low.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Not affected | ||
OpenShift Service Mesh 1 | kiali | Affected | ||
OpenShift Service Mesh 1 | servicemesh-grafana | Fix deferred | ||
OpenShift Service Mesh 2.0 | kiali | Not affected | ||
OpenShift Service Mesh 2.0 | servicemesh-grafana | Will not fix | ||
Red Hat Advanced Cluster Management for Kubernetes 2 | y18n | Affected | ||
Red Hat OpenShift Container Platform 3.11 | openshift3/ose-console | Fix deferred | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-console | Fix deferred | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-prometheus | Fix deferred | ||
Red Hat Openshift Data Foundation 4 | noobaa-core-container | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.3 High
CVSS3
Связанные уязвимости
The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.
The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.
The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Proto ...
Уязвимость библиотеки y18n прикладного программного обеспечения Аврора Центр, связанная с неконтролируемым изменением атрибутов прототипа объекта, позволяющая нарушителю реализовать атаку типа «загрязнение прототипа»
EPSS
7.3 High
CVSS3