Back

HIGH

hoek: Prototype pollution in utilities function

Published Mar 30, 2018

Description

hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge' and 'applyToDefaults' functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.

Affected products

Remediation

Red Hat statement

Red Hat Quay includes hoek as a dependency of protractor which is only used at build time. The vulnerable library is not used at runtime meaning this has a low impact on Red Hat Quay.

Metrics

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Mar 30, 2018
Updated Aug 5, 2024
Reserved Dec 28, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Feb 15, 2018
GHSA-JP4X-W63M-7WGM