nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payload
Published Mar 11, 2020
5.6
MEDIUMCVSS 3.1
EPSS 1.93%
Description
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
Affected products
- Vendor n/a Product Minimist Defaultn/a
- Version All versions prior to version 1.2.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Minimist | n/a |
|
No data.
OpenShift Service Mesh 1.0
servicemesh-grafana-0:6.2.2-36.el8
Fixed · RHSA-2020:2362
Openshift Service Mesh 1.0
jaeger-0:v1.13.1.redhat7-1.el7
Fixed · RHSA-2020:2362
Openshift Service Mesh 1.0
kiali-0:v1.0.11.redhat1-1.el7
Fixed · RHSA-2020:2362
Red Hat Enterprise Linux 8
nodejs:10-8020020200617141353.4cda2c84
Fixed · RHSA-2020:2848
Red Hat Enterprise Linux 8
nodejs:12-8020020200630155331.4cda2c84
Fixed · RHSA-2020:2852
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
nodejs:10-8000020200617115915.f8e95b4e
Fixed · RHSA-2020:3042
Red Hat Enterprise Linux 8.1 Extended Update Support
nodejs:10-8010020200617134056.c27ad7f8
Fixed · RHSA-2020:2849
Red Hat Enterprise Linux 8.1 Extended Update Support
nodejs:12-8010020200630154708.c27ad7f8
Fixed · RHSA-2020:2847
Red Hat OpenShift Container Platform 3.11
atomic-openshift-web-console-0:3.11.248-1.git.1.cc96c2d.el7
Fixed · RHSA-2020:2992
Red Hat OpenShift Container Platform 4.6
openshift4/ose-console:v4.6.0-202010100121.p0
Fixed · RHSA-2020:4298
Red Hat OpenShift Container Platform 4.6
openshift4/ose-logging-kibana6:v4.6.0-202107070256.p0.git.5ba5ae2
Fixed · RHSA-2021:2643
Red Hat OpenShift Container Platform 4.6
openshift4/ose-prometheus:v4.6.0-202009290409.p0
Fixed · RHSA-2020:4298
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs10-nodejs-0:10.21.0-3.el7
Fixed · RHSA-2020:3084
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs12-nodejs-0:12.18.2-1.el7
Fixed · RHSA-2020:2895
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs10-nodejs-0:10.21.0-3.el7
Fixed · RHSA-2020:3084
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs12-nodejs-0:12.18.2-1.el7
Fixed · RHSA-2020:2895
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs10-nodejs-0:10.21.0-3.el7
Fixed · RHSA-2020:3084
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs12-nodejs-0:12.18.2-1.el7
Fixed · RHSA-2020:2895
Red Hat Virtualization Engine 4.4
ovirt-engine-ui-extensions-0:1.2.2-1.el8ev
Fixed · RHSA-2020:3247
Logging Subsystem for Red Hat OpenShift
openshift-logging/kibana6-rhel8
Will not fix
Red Hat OpenShift Container Platform 3.11
kibana
Will not fix
Red Hat OpenShift Container Platform 3.11
openshift3/grafana
Will not fix
Red Hat OpenShift Container Platform 4
kibana
Will not fix
Red Hat OpenShift Container Platform 4
logging-kibana5-container
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-grafana
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-metering-hadoop
Will not fix
Red Hat Openshift Container Storage 4
ocs4/mcg-core-rhel8
Not affected
Red Hat Quay 3
nodejs-minimist
Fix deferred
Red Hat Software Collections
rh-nodejs10-nodejs-nodemon
Will not fix
Red Hat Software Collections
rh-nodejs12-nodejs-nodemon
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Service Mesh 1.0 | servicemesh-grafana-0:6.2.2-36.el8 | Fixed | RHSA-2020:2362 |
| Openshift Service Mesh 1.0 | jaeger-0:v1.13.1.redhat7-1.el7 | Fixed | RHSA-2020:2362 |
| Openshift Service Mesh 1.0 | kiali-0:v1.0.11.redhat1-1.el7 | Fixed | RHSA-2020:2362 |
| Red Hat Enterprise Linux 8 | nodejs:10-8020020200617141353.4cda2c84 | Fixed | RHSA-2020:2848 |
| Red Hat Enterprise Linux 8 | nodejs:12-8020020200630155331.4cda2c84 | Fixed | RHSA-2020:2852 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | nodejs:10-8000020200617115915.f8e95b4e | Fixed | RHSA-2020:3042 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | nodejs:10-8010020200617134056.c27ad7f8 | Fixed | RHSA-2020:2849 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | nodejs:12-8010020200630154708.c27ad7f8 | Fixed | RHSA-2020:2847 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-web-console-0:3.11.248-1.git.1.cc96c2d.el7 | Fixed | RHSA-2020:2992 |
| Red Hat OpenShift Container Platform 4.6 | openshift4/ose-console:v4.6.0-202010100121.p0 | Fixed | RHSA-2020:4298 |
| Red Hat OpenShift Container Platform 4.6 | openshift4/ose-logging-kibana6:v4.6.0-202107070256.p0.git.5ba5ae2 | Fixed | RHSA-2021:2643 |
| Red Hat OpenShift Container Platform 4.6 | openshift4/ose-prometheus:v4.6.0-202009290409.p0 | Fixed | RHSA-2020:4298 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs10-nodejs-0:10.21.0-3.el7 | Fixed | RHSA-2020:3084 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs12-nodejs-0:12.18.2-1.el7 | Fixed | RHSA-2020:2895 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs10-nodejs-0:10.21.0-3.el7 | Fixed | RHSA-2020:3084 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs12-nodejs-0:12.18.2-1.el7 | Fixed | RHSA-2020:2895 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs10-nodejs-0:10.21.0-3.el7 | Fixed | RHSA-2020:3084 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs12-nodejs-0:12.18.2-1.el7 | Fixed | RHSA-2020:2895 |
| Red Hat Virtualization Engine 4.4 | ovirt-engine-ui-extensions-0:1.2.2-1.el8ev | Fixed | RHSA-2020:3247 |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.11 | kibana | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift3/grafana | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | kibana | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | logging-kibana5-container | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-grafana | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-metering-hadoop | Will not fix | n/a |
| Red Hat Openshift Container Storage 4 | ocs4/mcg-core-rhel8 | Not affected | n/a |
| Red Hat Quay 3 | nodejs-minimist | Fix deferred | n/a |
| Red Hat Software Collections | rh-nodejs10-nodejs-nodemon | Will not fix | n/a |
| Red Hat Software Collections | rh-nodejs12-nodejs-nodemon | Will not fix | n/a |
minimist
npm
Introduced 0 Fixed 0.2.1minimist
npm
Introduced 1.0.0 Fixed 1.2.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | minimist | 0 | 0.2.1 |
| npm | minimist | 1.0.0 | 1.2.3 |
Remediation
Red Hat statement
Red Hat Quay only includes minimist as a dependency of the test suites, and it not include it in the product. We may fix this issue in a future Red Hat Quay release.
References (13)
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00024.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-7598 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1813344 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-0395 Advisory
- https://github.com/advisories/GHSA-vh95-rmgr-6w4m Advisory
- https://github.com/minimistjs/minimist/commit/10bd4cdf49d9686d48214be9d579a9cdfda37c68
- https://github.com/minimistjs/minimist/commit/38a4d1caead72ef99e824bb420a2528eec03d9ab
- https://github.com/minimistjs/minimist/commit/4cf1354839cb972e38496d35e12f806eea92c11f#diff-a1e0ee62c91705696ddb71aa30ad4f95
- https://github.com/minimistjs/minimist/commit/63e7ed05aa4b1889ec2f3b196426db4500cbda94
- https://nvd.nist.gov/vuln/detail/CVE-2020-7598
- https://snyk.io/vuln/SNYK-JS-MINIMIST-559764 x_refsource_MISCExploitPatchThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-7598
- https://www.npmjs.com/advisories/1179
Change history (0)
No recorded changes yet.