Описание
This affects the package mpath before 0.8.4. A type confusion vulnerability can lead to a bypass of CVE-2018-16490. In particular, the condition ignoreProperties.indexOf(parts[i]) !== -1 returns -1 if parts[i] is ['proto']. This is because the method that has been called if the input is an array is Array.prototype.indexOf() and not String.prototype.indexOf(). They behave differently depending on the type of the input.
A vulnerability CVE-2018-16490 allowed for prototype pollution module mpath <0.5.1. The vulnerability allowed an attacker to inject arbitrary properties onto Object.prototype. The issue was resolved in mpath 0.5.1, however the proposed fix was vulnerable to type confusion. The type confusion allows for bypassing the existing protection leading to prototype pollution.
Отчет
The vulnerable component is no longer shipped with Red Hat Advanced Cluster Management for Kubernetes.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 | mpath | Not affected |
Показывать по
Дополнительная информация
Статус:
5.6 Medium
CVSS3
Связанные уязвимости
This affects the package mpath before 0.8.4. A type confusion vulnerability can lead to a bypass of CVE-2018-16490. In particular, the condition ignoreProperties.indexOf(parts[i]) !== -1 returns -1 if parts[i] is ['__proto__']. This is because the method that has been called if the input is an array is Array.prototype.indexOf() and not String.prototype.indexOf(). They behave differently depending on the type of the input.
5.6 Medium
CVSS3