Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-21489

Опубликовано: 01 окт. 2024
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to missing check if the attribute resolves to the object prototype.

A flaw was found in uPlot. This vulnerability allows prototype pollution via the uplot.assign function due to missing checks for attributes that resolve to the object prototype.

Отчет

Grafana is not impacted by this CVE, as the vulnerable uplot.assign function is not utilized in Grafana on Red Hat Enterprise Linux. Only RHEL-8.4.z having the issue.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10grafanaNot affected
Red Hat Enterprise Linux 8grafanaAffected
Red Hat Enterprise Linux 9grafanaNot affected
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportgrafanaFixedRHSA-2024:808314.10.2024
Red Hat Enterprise Linux 8.4 Telecommunications Update ServicegrafanaFixedRHSA-2024:808314.10.2024
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsgrafanaFixedRHSA-2024:808314.10.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1321
https://bugzilla.redhat.com/show_bug.cgi?id=2315838uplot: Prototype Pollution in uplot

EPSS

Процентиль: 37%
0.00159
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
nvd
больше 1 года назад

Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to missing check if the attribute resolves to the object prototype.

CVSS3: 8.2
github
больше 1 года назад

uPlot Prototype Pollution vulnerability

EPSS

Процентиль: 37%
0.00159
Низкий

8.2 High

CVSS3