Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-8116

Опубликовано: 28 янв. 2020
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language constructs such as objects.

A prototype pollution flaw was found in nodejs-dot-prop. The function set could be tricked into adding or modifying properties of Object.prototype using any of the constructor, prototype, or proto paths. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Отчет

In both OpenShift Container Platform (OCP) and OpenShift ServiceMesh (OSSM), the grafana and prometheus containers are behind OpenShift OAuth restricting access to the vulnerable dot-prop library to authenticated users only, therefore the impact is Low. Red Hat Openshift Container Storage 4 is not affected by this vulnerability, as it already includes patched version of dot-prop(v5.2.0) in noobaa-core container.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 1servicemesh-grafanaFix deferred
Red Hat Enterprise Linux 8nodejs:14/nodejsNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-grafanaFix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-prometheusNot affected
Red Hat Openshift Container Storage 4ocs4/mcg-core-rhel8Not affected
Red Hat Software Collectionsrh-nodejs14-nodejsNot affected
Red Hat Enterprise Linux 8nodejsFixedRHSA-2020:427219.10.2020
Red Hat Enterprise Linux 8nodejsFixedRHSA-2021:054816.02.2021
Red Hat Enterprise Linux 8.1 Extended Update SupportnodejsFixedRHSA-2020:490304.11.2020
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-nodejs12-nodejsFixedRHSA-2020:508612.11.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-471
https://bugzilla.redhat.com/show_bug.cgi?id=1868196nodejs-dot-prop: prototype pollution

EPSS

Процентиль: 55%
0.0033
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
больше 5 лет назад

Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language constructs such as objects.

CVSS3: 7.3
nvd
больше 5 лет назад

Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language constructs such as objects.

CVSS3: 7.3
debian
больше 5 лет назад

Prototype pollution vulnerability in dot-prop npm package versions bef ...

CVSS3: 7.3
github
почти 5 лет назад

dot-prop Prototype Pollution vulnerability

CVSS3: 7.3
fstec
около 4 лет назад

Уязвимость библиотеки dot-prop прикладного программного обеспечения Аврора Центр, связанная с неконтролируемым изменением атрибутов прототипа объекта, позволяющая нарушителю реализовать атаку типа «загрязнение прототипа»

EPSS

Процентиль: 55%
0.0033
Низкий

7.3 High

CVSS3