Описание
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
A flaw was found in nodejs-lodash in versions 4.17.15 and earlier. A prototype pollution attack is possible which can lead to arbitrary code execution. The primary threat from this vulnerability is to data integrity and system availability.
Отчет
In OpenShift ServiceMesh (OSSM), Red Hat OpenShift Jaeger (RHOSJ) and Red Hat OpenShift Container Platform (RHOCP), the affected containers are behind OpenShift OAuth authentication. This restricts access to the vulnerable nodejs-lodash library to authenticated users only, therefore the impact is low. Red Hat OpenShift Container Platform 4 delivers the kibana package where the nodejs-lodash library is used, but due to the code changing to the container first content the kibana package is marked as wontfix. This may be fixed in the future. Red Hat Virtualization uses vulnerable version of nodejs-lodash, however zipObjectDeep is not used, therefore the impact is low.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
OpenShift Service Mesh 1 | jaeger | Out of support scope | ||
Red Hat OpenShift Container Platform 3.11 | kibana | Will not fix | ||
Red Hat OpenShift Container Platform 3.11 | openshift3/grafana | Fix deferred | ||
Red Hat OpenShift Container Platform 3.11 | openshift3/ose-console | Fix deferred | ||
Red Hat OpenShift Container Platform 4 | kibana | Will not fix | ||
Red Hat OpenShift Container Platform 4 | logging-kibana5-container | Fix deferred | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-console | Fix deferred | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-grafana | Fix deferred | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-jenkins-agent-nodejs | Not affected | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-metering-hadoop | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
7.4 High
CVSS3
Связанные уязвимости
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
Prototype pollution attack when using _.zipObjectDeep in lodash before ...
Уязвимость реализации метода _.zipObjectDeep() библиотеки Lodash, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
EPSS
7.4 High
CVSS3