Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') Affecting nodejs-packaging package, versions <0:17-3.module+el8.1.0+5392+4d6b561f
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-ORACLE8-NODEJSPACKAGING-2575897
- published 10 Apr 2022
- disclosed 15 Jul 2020
Introduced: 15 Jul 2020
CVE-2020-15366 Open this link in a new tabHow to fix?
Upgrade Oracle:8
nodejs-packaging
to version 0:17-3.module+el8.1.0+5392+4d6b561f or higher.
This issue was patched in ELSA-2021-0548
.
NVD Description
Note: Versions mentioned in the description apply only to the upstream nodejs-packaging
package and not the nodejs-packaging
package as distributed by Oracle
.
See How to fix?
for Oracle:8
relevant fixed versions and status.
An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an untrusted schema should be a denial of service, not execution of code.)
References
- https://linux.oracle.com/cve/CVE-2020-15366.html
- https://linux.oracle.com/errata/ELSA-2020-5499.html
- https://linux.oracle.com/errata/ELSA-2021-0548.html
- https://linux.oracle.com/errata/ELSA-2021-0551.html
- https://github.com/ajv-validator/ajv/releases/tag/v6.12.3
- https://github.com/ajv-validator/ajv/tags
- https://hackerone.com/bugs?subject=user&report_id=894259
- https://security.netapp.com/advisory/ntap-20240621-0007/