MEDIUM
mquery: Code injection via merge or clone operation
Published Dec 11, 2020
5.3
MEDIUMCVSS 3.1
EPSS 1.04%
Description
lib/utils.js in mquery before 3.2.3 allows a pollution attack because a special property (e.g., __proto__) can be copied during a merge or clone operation.
Affected products
No data.
- < 3.2.3
No data.
Red Hat Advanced Cluster Management for Kubernetes 2.1 for RHEL 8
rhacm2/acm-must-gather-rhel8:v2.1.6-6
Fixed · RHSA-2021:1369
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2.1 for RHEL 8 | rhacm2/acm-must-gather-rhel8:v2.1.6-6 | Fixed | RHSA-2021:1369 |
mquery
npm
Introduced 0 Fixed 3.2.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | mquery | 0 | 3.2.3 |
Remediation
Red Hat statement
The affected version of mquery is a dependency of the mongoose library. The exploitation of this vulnerability requires authenticated access, consequently, the CVSSv3 score for RHACM is lower than the score of the flaw.
Weaknesses (1)
References (7)
- https://access.redhat.com/security/cve/CVE-2020-35149 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1929338 Issue Tracking
- https://github.com/advisories/GHSA-45q2-34rf-mr94 Advisory
- https://github.com/aheckmann/mquery/commit/792e69fd0a7281a0300be5cade5a6d7c1d468ad4 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-35149
- https://portswigger.net/daily-swig/prototype-pollution-the-dangerous-and-underrated-vulnerability-impacting-javascript-applications
- https://www.cve.org/CVERecord?id=CVE-2020-35149
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 11, 2020
Updated Aug 4, 2024
Reserved Dec 11, 2020
Link CVE-2020-35149
CISA Vulnrichment
GHSA-45Q2-34RF-MR94 Updated n/a