nodejs-ajv: prototype pollution via crafted JSON schema in ajv.validate function
Published Jul 15, 2020
5.6
MEDIUMCVSS 3.1
EPSS 2.31%
Description
An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an untrusted schema should be a denial of service, not execution of code.)
Affected products
No data.
No data.
Red Hat Automation Hub 4.2 for RHEL 7
automation-hub-0:4.2.2-1.el7pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 7
python-bleach-0:3.3.0-1.el7pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 7
python-bleach-allowlist-0:1.0.3-1.el7pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 7
python-galaxy-importer-0:0.2.15-1.el7pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 7
python-galaxy-ng-0:4.2.2-1.el7pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 7
python-pulp-ansible-1:0.5.6-1.el7pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 7
python3-django-0:2.2.18-1.el7pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 8
automation-hub-0:4.2.2-1.el8pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 8
python-bleach-0:3.3.0-1.el8pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 8
python-bleach-allowlist-0:1.0.3-1.el8pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 8
python-galaxy-importer-0:0.2.15-1.el8pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 8
python-galaxy-ng-0:4.2.2-1.el8pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 8
python-pulp-ansible-1:0.5.6-1.el8pc
Fixed · RHSA-2021:0781
Red Hat Automation Hub 4.2 for RHEL 8
python3-django-0:2.2.18-1.el8pc
Fixed · RHSA-2021:0781
Red Hat Enterprise Linux 8
nodejs:10-8030020210118191659.229f0a1c
Fixed · RHSA-2021:0548
Red Hat Enterprise Linux 8
nodejs:12-8030020201124152102.229f0a1c
Fixed · RHSA-2020:5499
Red Hat Enterprise Linux 8
nodejs:14-8030020210126165503.229f0a1c
Fixed · RHSA-2021:0551
Red Hat OpenShift Container Platform 4.6
openshift4/ose-console:v4.6.0-202010100121.p0
Fixed · RHSA-2020:4298
Red Hat OpenShift Container Platform 4.6
openshift4/ose-prometheus:v4.6.0-202009290409.p0
Fixed · RHSA-2020:4298
Red Hat Quay 3
quay/quay-rhel8:v3.6.0-62
Fixed · RHSA-2021:3917
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs10-nodejs-0:10.23.1-2.el7
Fixed · RHSA-2021:0521
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs12-nodejs-0:12.19.1-2.el7
Fixed · RHSA-2020:5305
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs14-nodejs-0:14.15.4-2.el7
Fixed · RHSA-2021:0421
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs10-nodejs-0:10.23.1-2.el7
Fixed · RHSA-2021:0521
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs12-nodejs-0:12.19.1-2.el7
Fixed · RHSA-2020:5305
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs14-nodejs-0:14.15.4-2.el7
Fixed · RHSA-2021:0421
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs10-nodejs-0:10.23.1-2.el7
Fixed · RHSA-2021:0521
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs12-nodejs-0:12.19.1-2.el7
Fixed · RHSA-2020:5305
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs14-nodejs-0:14.15.4-2.el7
Fixed · RHSA-2021:0421
OpenShift Service Mesh 1
kiali
Fix deferred
OpenShift Service Mesh 1
servicemesh-grafana
Fix deferred
Red Hat OpenShift Container Platform 3.11
openshift3/ose-console
Fix deferred
Red Hat OpenShift Container Platform 4
openshift4/ose-grafana
Fix deferred
Red Hat OpenShift Virtualization 1
kubevirt-web-ui
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Automation Hub 4.2 for RHEL 7 | automation-hub-0:4.2.2-1.el7pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 7 | python-bleach-0:3.3.0-1.el7pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 7 | python-bleach-allowlist-0:1.0.3-1.el7pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 7 | python-galaxy-importer-0:0.2.15-1.el7pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 7 | python-galaxy-ng-0:4.2.2-1.el7pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 7 | python-pulp-ansible-1:0.5.6-1.el7pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 7 | python3-django-0:2.2.18-1.el7pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 8 | automation-hub-0:4.2.2-1.el8pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 8 | python-bleach-0:3.3.0-1.el8pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 8 | python-bleach-allowlist-0:1.0.3-1.el8pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 8 | python-galaxy-importer-0:0.2.15-1.el8pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 8 | python-galaxy-ng-0:4.2.2-1.el8pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 8 | python-pulp-ansible-1:0.5.6-1.el8pc | Fixed | RHSA-2021:0781 |
| Red Hat Automation Hub 4.2 for RHEL 8 | python3-django-0:2.2.18-1.el8pc | Fixed | RHSA-2021:0781 |
| Red Hat Enterprise Linux 8 | nodejs:10-8030020210118191659.229f0a1c | Fixed | RHSA-2021:0548 |
| Red Hat Enterprise Linux 8 | nodejs:12-8030020201124152102.229f0a1c | Fixed | RHSA-2020:5499 |
| Red Hat Enterprise Linux 8 | nodejs:14-8030020210126165503.229f0a1c | Fixed | RHSA-2021:0551 |
| Red Hat OpenShift Container Platform 4.6 | openshift4/ose-console:v4.6.0-202010100121.p0 | Fixed | RHSA-2020:4298 |
| Red Hat OpenShift Container Platform 4.6 | openshift4/ose-prometheus:v4.6.0-202009290409.p0 | Fixed | RHSA-2020:4298 |
| Red Hat Quay 3 | quay/quay-rhel8:v3.6.0-62 | Fixed | RHSA-2021:3917 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs10-nodejs-0:10.23.1-2.el7 | Fixed | RHSA-2021:0521 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs12-nodejs-0:12.19.1-2.el7 | Fixed | RHSA-2020:5305 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs14-nodejs-0:14.15.4-2.el7 | Fixed | RHSA-2021:0421 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs10-nodejs-0:10.23.1-2.el7 | Fixed | RHSA-2021:0521 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs12-nodejs-0:12.19.1-2.el7 | Fixed | RHSA-2020:5305 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs14-nodejs-0:14.15.4-2.el7 | Fixed | RHSA-2021:0421 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs10-nodejs-0:10.23.1-2.el7 | Fixed | RHSA-2021:0521 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs12-nodejs-0:12.19.1-2.el7 | Fixed | RHSA-2020:5305 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs14-nodejs-0:14.15.4-2.el7 | Fixed | RHSA-2021:0421 |
| OpenShift Service Mesh 1 | kiali | Fix deferred | n/a |
| OpenShift Service Mesh 1 | servicemesh-grafana | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift3/ose-console | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-grafana | Fix deferred | n/a |
| Red Hat OpenShift Virtualization 1 | kubevirt-web-ui | Will not fix | n/a |
ajv
npm
Introduced 0 Fixed 6.12.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | ajv | 0 | 6.12.3 |
Remediation
Red Hat statement
In both OpenShift Container Platform (OCP) and OpenShift ServiceMesh (OSSM), the affected containers are behind OpenShift OAuth authentication. This restricts access to the vulnerable nodejs-ajv library to authenticated users only, therefore the impact is low.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (17 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 2.31% (0.02313) | 82.80th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.31% (0.02313) | 81.10th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.45% (0.00451) | 61.61th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.37% (0.00370) | 73.46th | v3 (v2023.03.01) |
| Jun 22, 2024 | 0.37% (0.00370) | 72.73th | v3 (v2023.03.01) |
| May 19, 2024 | 0.31% (0.00308) | 69.85th | v3 (v2023.03.01) |
| May 4, 2024 | 0.32% (0.00318) | 70.27th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.30% (0.00303) | 68.84th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.30% (0.00303) | 65.82th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.24% (0.00240) | 60.17th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.40% (0.02398) | 81.51th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.40% (0.02398) | 79.76th | v2 (v2022.01.01) |
| Feb 4, 2022 | 10.05% (0.10055) | 87.55th | v2 (v2022.01.01) |
| Feb 3, 2022 | 7.64% (0.07644) | 84.07th | v1 |
| Jan 6, 2022 | 7.64% (0.07644) | 83.92th | v1 |
| Jan 5, 2022 | 1.81% (0.01811) | 75.27th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.81% (0.01811) | 0.00th | v1 |
References (11)
- https://access.redhat.com/security/cve/CVE-2020-15366 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1857977 Issue Tracking
- https://github.com/advisories/GHSA-v88g-cgmw-v5xw Advisory
- https://github.com/ajv-validator/ajv/commit/65b2f7d76b190ac63a0d4e9154c712d7aa37049f
- https://github.com/ajv-validator/ajv/releases/tag/v6.12.3 Release NotesThird Party Advisory
- https://github.com/ajv-validator/ajv/tags Third Party Advisory
- https://hackerone.com/bugs?subject=user&report_id=894259 Permissions Required
- https://nvd.nist.gov/vuln/detail/CVE-2020-15366
- https://security.netapp.com/advisory/ntap-20240621-0007
- https://snyk.io/vuln/SNYK-JS-AJV-584908
- https://www.cve.org/CVERecord?id=CVE-2020-15366
Change history (0)
No recorded changes yet.