nodejs-extend: Prototype pollution in Object.prototype
Published Feb 1, 2019
9.8
CRITICALCVSS 3.0
EPSS 1.72%
Description
A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype.
Affected products
-
- Version <1.1.7, ~<2.0.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| HackerOne | Node.extend | n/a |
|
- < 1.1.7
- ≥ 2.0.0 · < 2.0.1
No data.
Red Hat Mobile Application Platform 4
nodejs-extend
Not affected
Red Hat OpenShift Container Platform 3.10
jenkins-slave-nodejs
Not affected
Red Hat OpenShift Container Platform 3.10
logging-auth-proxy
Not affected
Red Hat OpenShift Container Platform 3.10
logging-kibana
Not affected
Red Hat Software Collections
rh-nodejs6-nodejs-extend
Not affected
Red Hat Software Collections
rh-nodejs8-nodejs
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Mobile Application Platform 4 | nodejs-extend | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.10 | jenkins-slave-nodejs | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.10 | logging-auth-proxy | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.10 | logging-kibana | Not affected | n/a |
| Red Hat Software Collections | rh-nodejs6-nodejs-extend | Not affected | n/a |
| Red Hat Software Collections | rh-nodejs8-nodejs | Not affected | n/a |
node.extend
npm
Introduced 0 Fixed 1.1.7node.extend
npm
Introduced 2.0.0 Fixed 2.0.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | node.extend | 0 | 1.1.7 |
| npm | node.extend | 2.0.0 | 2.0.1 |
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2018-16491 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1672400 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0337 Advisory
- https://github.com/advisories/GHSA-r96c-57pf-9jjm Advisory
- https://hackerone.com/reports/430831 x_refsource_MISCExploitIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-16491
- https://www.cve.org/CVERecord?id=CVE-2018-16491
- https://www.npmjs.com/advisories/781
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-16491 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1672400 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0337 | Advisory | |
| https://github.com/advisories/GHSA-r96c-57pf-9jjm | Advisory | |
| https://hackerone.com/reports/430831 | x_refsource_MISCExploitIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-16491 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-16491 | ||
| https://www.npmjs.com/advisories/781 |
Change history (0)
No recorded changes yet.