Описание
Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
An Uncontrolled Resource Consumption flaw was found in minimist. The original fix for CVE-2020-7598 was incomplete as it was still possible to bypass in some cases. This flaw (CVE-2021-44906) allows an attacker to trick the library into adding or modifying the properties of Object.prototype, using a constructor or proto payload, resulting in prototype pollution and loss of confidentiality, availability, and integrity.
Отчет
As minimist is an argument parsing module for nodejs, exploitation of this vulnerability requires an attacker to influence which arguments are passed to nodejs when running a script. Red Hat products and services are designed in such a way that gaining this ability is not trivial. Additionally, the impact is limited by only enabling the pollution of functions, and not all generic objects. Within Red Hat Satellite 6 this flaw has been rated as having a security impact of Low. It is not currently planned to be addressed there, as the minimist library is only included in the -doc subpackage and is part of test fixtures that are not in the execution path used by the rabl gem.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Not affected | ||
Migration Toolkit for Containers | rhmtc/openshift-migration-ui-rhel8 | Affected | ||
Red Hat 3scale API Management Platform 2 | 3scale-apicast-operator-bundle-container | Affected | ||
Red Hat 3scale API Management Platform 2 | 3scale-apicast-operator-container | Affected | ||
Red Hat Enterprise Linux 8 | nodejs:12/nodejs | Out of support scope | ||
Red Hat Enterprise Linux 8 | nodejs:12/nodejs-nodemon | Out of support scope | ||
Red Hat Fuse 7 | io.apicurio-apicurito | Will not fix | ||
Red Hat Fuse 7 | io.hawt-hawtio-online | Will not fix | ||
Red Hat Fuse 7 | io.syndesis-syndesis-ui | Will not fix | ||
Red Hat JBoss Enterprise Application Platform Expansion Pack | org.jboss.hal-hal-parent | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
3.1 Low
CVSS3
Связанные уязвимости
Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.j ...
EPSS
3.1 Low
CVSS3