Prototype Pollution
Published Dec 16, 2020
7.3
HIGHCVSS 3.1
EPSS 3.72%
Description
All versions of package datatables.net are vulnerable to Prototype Pollution due to an incomplete fix for https://snyk.io/vuln/SNYK-JS-DATATABLESNET-598806.
Affected products
- Vendor n/a Product Datatables.net Defaultunknown
Affected
- ≥ 0, < unspecified
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Datatables.net | unknown | Affected
|
- < 1.10.23
No data.
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
cockpit-ovirt-0:0.14.20-1.el8ev
Fixed · RHSA-2021:1184
Red Hat Virtualization Engine 4.4
ovirt-engine-ui-extensions-0:1.2.5-1.el8ev
Fixed · RHSA-2021:1186
Red Hat Virtualization Engine 4.4
ovirt-web-ui-0:1.6.7-1.el8ev
Fixed · RHSA-2021:1169
OpenShift Service Mesh 1
kiali
Out of support scope
Red Hat OpenShift Container Platform 3.11
openshift3/ose-console
Fix deferred
Red Hat OpenShift Container Platform 4
openshift4/ose-console
Fix deferred
Red Hat Single Sign-On 7
keycloak-theme
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | cockpit-ovirt-0:0.14.20-1.el8ev | Fixed | RHSA-2021:1184 |
| Red Hat Virtualization Engine 4.4 | ovirt-engine-ui-extensions-0:1.2.5-1.el8ev | Fixed | RHSA-2021:1186 |
| Red Hat Virtualization Engine 4.4 | ovirt-web-ui-0:1.6.7-1.el8ev | Fixed | RHSA-2021:1169 |
| OpenShift Service Mesh 1 | kiali | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift3/ose-console | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-console | Fix deferred | n/a |
| Red Hat Single Sign-On 7 | keycloak-theme | Will not fix | n/a |
datatables.net
npm
Introduced 0 Fixed 1.10.22
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | datatables.net | 0 | 1.10.22 |
Remediation
Red Hat statement
OpenShift console container does package a vulnerable version of datatables.net, however as access to the vulnerable component is restricted via OpenShift OAuth the vulnerability is rated with an impact of `Low`.
References (13)
- https://access.redhat.com/security/cve/CVE-2020-28458 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1908441 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-1499 Advisory
- https://github.com/DataTables/DataTablesSrc/commit/a51cbe99fd3d02aa5582f97d4af1615d11a1ea03 PatchThird Party Advisory
- https://github.com/DataTables/Dist-DataTables/blob/master/js/jquery.dataTables.js%23L2766 Broken LinkThird Party Advisory
- https://github.com/advisories/GHSA-m7j4-fhg6-xf5v Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-28458
- https://security.netapp.com/advisory/ntap-20240621-0006
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1051961 Third Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1051962 Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-DATATABLESNET-1016402 Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-DATATABLESNET-598806 ExploitThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-28458
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-28458 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1908441 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-1499 | Advisory | |
| https://github.com/DataTables/DataTablesSrc/commit/a51cbe99fd3d02aa5582f97d4af1615d11a1ea03 | PatchThird Party Advisory | |
| https://github.com/DataTables/Dist-DataTables/blob/master/js/jquery.dataTables.js%23L2766 | Broken LinkThird Party Advisory | |
| https://github.com/advisories/GHSA-m7j4-fhg6-xf5v | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-28458 | ||
| https://security.netapp.com/advisory/ntap-20240621-0006 | ||
| https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1051961 | Third Party Advisory | |
| https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1051962 | Third Party Advisory | |
| https://snyk.io/vuln/SNYK-JS-DATATABLESNET-1016402 | Third Party Advisory | |
| https://snyk.io/vuln/SNYK-JS-DATATABLESNET-598806 | ExploitThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-28458 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub