Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3805

Опубликовано: 13 сент. 2021
Источник: redhat
CVSS3: 7.5

Описание

object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

A flaw was found in the object-path nodejs library when the del() function is called to validate object properties. An attacker can manipulate or alter the prototype of an object causing the modification of default properties on all objects. This could lead into a service disruption or a denial of service attack (DoS).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 1servicemesh-prometheusOut of support scope
OpenShift Service Mesh 2.0servicemesh-prometheusAffected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/application-ui-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-api-rhel8Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/grc-ui-rhel8Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/mcm-topology-api-rhel8Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8rhacm2/grc-ui-api-rhel8FixedRHSA-2021:392520.10.2021
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8rhacm2/search-api-rhel8FixedRHSA-2021:392520.10.2021
Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8rhacm2/search-ui-rhel8FixedRHSA-2021:392520.10.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-915
https://bugzilla.redhat.com/show_bug.cgi?id=2006397nodejs-object-path: prototype pollution vulnerability

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CVSS3: 7.5
nvd
больше 4 лет назад

object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CVSS3: 7.5
debian
больше 4 лет назад

object-path is vulnerable to Improperly Controlled Modification of Obj ...

CVSS3: 7.5
github
больше 4 лет назад

Prototype Pollution in object-path

7.5 High

CVSS3