nodejs-extend: Prototype pollution can allow attackers to modify object properties
Published Feb 1, 2019
9.8
CRITICALCVSS 3.0
EPSS 3.05%
Description
A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.prototype.
Affected products
-
- Version < 2.0.2, ~<3.0.2StatusaffectedConstraints-
- Version
- < 2.0.2
- ≥ 3.0.0 · < 3.0.2
No data.
Red Hat Quay 3
quay/quay-rhel8:v3.6.0-62
Fixed · RHSA-2021:3917
Red Hat Mobile Application Platform 4
nodejs-extend
Not affected
Red Hat OpenShift Container Platform 3.10
jenkins-slave-nodejs
Not affected
Red Hat OpenShift Container Platform 3.10
logging-auth-proxy
Not affected
Red Hat OpenShift Container Platform 3.10
logging-kibana
Not affected
Red Hat Software Collections
rh-nodejs6-nodejs-extend
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Quay 3 | quay/quay-rhel8:v3.6.0-62 | Fixed | RHSA-2021:3917 |
| Red Hat Mobile Application Platform 4 | nodejs-extend | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.10 | jenkins-slave-nodejs | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.10 | logging-auth-proxy | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.10 | logging-kibana | Not affected | n/a |
| Red Hat Software Collections | rh-nodejs6-nodejs-extend | Will not fix | n/a |
extend
npm
Introduced 3.0.0 Fixed 3.0.2extend
npm
Introduced 1.1.3 Fixed 2.0.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | extend | 3.0.0 | 3.0.2 |
| npm | extend | 1.1.3 | 2.0.2 |
Remediation
Red Hat statement
Red Hat Quay includes 'extend' as a build time dependency. It's not used at runtime reducing the impact of this vulnerability to low.
References (10)
- https://access.redhat.com/security/cve/CVE-2018-16492 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1608140 Issue Tracking
- https://github.com/advisories/GHSA-qrmc-fj45-qfc2 Advisory
- https://github.com/github/advisory-database/pull/6695
- https://github.com/justmoon/node-extend/commit/0e68e71d93507fcc391e398bc84abd0666b28190
- https://github.com/justmoon/node-extend/pull/48
- https://hackerone.com/reports/381185 x_refsource_MISCExploitIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-16492
- https://snyk.io/vuln/npm:extend:20180424
- https://www.cve.org/CVERecord?id=CVE-2018-16492
Change history (0)
No recorded changes yet.