nodejs-getobject: Prototype pollution could result in DoS and RCE
Published Dec 29, 2020
9.8
CRITICALCVSS 3.1
EPSS 4.24%
Description
Prototype pollution vulnerability in 'getobject' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution.
Affected products
- Vendor n/a Product Getobject Defaultn/a
- Version 0.1.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Getobject | n/a |
|
- 0.1.0
No data.
OpenShift Service Mesh 1
servicemesh-grafana
Not affected
OpenShift Service Mesh 2.0
servicemesh-grafana
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Service Mesh 1 | servicemesh-grafana | Not affected | n/a |
| OpenShift Service Mesh 2.0 | servicemesh-grafana | Not affected | n/a |
getobject
npm
Introduced 0 Fixed 1.0.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | getobject | 0 | 1.0.0 |
Remediation
Red Hat statement
In OpenShift ServiceMesh (OSSM) the affected components are behind OpenShift OAuth authentication. This restricts access to the vulnerable nodejs-getobject library to authenticated users only, therefore the impact is Low. OpenShift ServiceMesh (OSSM) 1.1 is out of support scope for Moderate and Low impact vulnerabilities, hence is marked Out Of Support Scope.
References (8)
- https://access.redhat.com/security/cve/CVE-2020-28282 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1912463 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-2181 Advisory
- https://github.com/advisories/GHSA-957j-59c2-j692 Advisory
- https://github.com/cowboy/node-getobject/blob/aba04a8e1d6180eb39eff09990c3a43886ba8937/lib/getobject.js#L48 x_refsource_MISCExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-28282
- https://www.cve.org/CVERecord?id=CVE-2020-28282
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2020-28282 x_refsource_CONFIRMExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-28282 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1912463 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-2181 | Advisory | |
| https://github.com/advisories/GHSA-957j-59c2-j692 | Advisory | |
| https://github.com/cowboy/node-getobject/blob/aba04a8e1d6180eb39eff09990c3a43886ba8937/lib/getobject.js#L48 | x_refsource_MISCExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-28282 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-28282 | ||
| https://www.whitesourcesoftware.com/vulnerability-database/CVE-2020-28282 | x_refsource_CONFIRMExploitThird Party Advisory |
Change history (0)
No recorded changes yet.