Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-29063

Опубликовано: 06 мар. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.

A flaw was found in Immutable.js, a library for persistent immutable data structures. This vulnerability, known as Prototype Pollution, allows an attacker with low privileges to inject unwanted properties into core JavaScript object prototypes without user interaction. By manipulating specific APIs such as mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject(), a remote attacker could potentially execute arbitrary code or cause a denial of service (DoS).

Отчет

Exploitation of this vulnerability requires that an attacker is able to provide arbitrary data to clients of this library in a way that calls the affected functions with data the attacker controls. In most deployments, the ability to provide data in this fashion requires that an attacker has some degree of privileges to access the affected applications.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-view-plugin-rhel9Will not fix
Node HealthCheck Operatorworkload-availability/node-healthcheck-must-gather-rhel9Not affected
Node HealthCheck Operatorworkload-availability/node-healthcheck-operator-bundleNot affected
Node HealthCheck Operatorworkload-availability/node-healthcheck-rhel9-operatorNot affected
Node HealthCheck Operatorworkload-availability/node-remediation-console-rhel8Affected
Node HealthCheck Operatorworkload-availability/node-remediation-console-rhel9Affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-console-plugin-pf5-rhel9Affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-console-plugin-rhel9Affected
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-rhel8Will not fix
OpenShift Service Mesh 3openshift-service-mesh/kiali-operator-bundleNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-915
https://bugzilla.redhat.com/show_bug.cgi?id=2445291immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution

EPSS

Процентиль: 59%
0.00978
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
5 месяцев назад

Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.

CVSS3: 9.8
nvd
5 месяцев назад

Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.

CVSS3: 9.8
debian
5 месяцев назад

Immutable.js provides many Persistent Immutable data structures. Prior ...

CVSS3: 9.8
github
5 месяцев назад

Immutable is vulnerable to Prototype Pollution

EPSS

Процентиль: 59%
0.00978
Низкий

8.8 High

CVSS3