Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3757

Опубликовано: 30 авг. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

immer is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

A flaw was found in immer when manipulates object attributes such as proto, constructor and prototype. An attacker can manipulate these values by overwriting and polluting them. Those attributes would be inherited by JavaScript objects which could trigger exception handlers and leading into a denial of service attack.

Отчет

In OpenShift Container Platform (OCP) and OpenShift Migration Toolkit for Containers (MTC), the affected components are behind OpenShift OAuth authentication. This restricts access to the vulnerable nodejs-immer library to authenticated users only, therefore the impact is Low.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 1servicemesh-grafanaOut of support scope
OpenShift Service Mesh 1servicemesh-prometheusOut of support scope
OpenShift Service Mesh 2.0servicemesh-grafanaAffected
OpenShift Service Mesh 2.0servicemesh-prometheusAffected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel8Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/kui-web-terminal-rhel8Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/search-ui-rhel8Affected
Red Hat OpenShift Container Platform 4openshift4/ose-grafanaFix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-prometheusFix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-thanos-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-915
https://bugzilla.redhat.com/show_bug.cgi?id=2000734nodejs-immer: prototype pollution may lead to DoS or remote code execution

EPSS

Процентиль: 69%
0.00592
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

immer is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CVSS3: 7.5
github
больше 4 лет назад

Prototype Pollution in immer

EPSS

Процентиль: 69%
0.00592
Низкий

7.5 High

CVSS3