Back

MEDIUM

nodejs-minimist: prototype pollution allows adding or modifying properties of Object.prototype using a constructor or __proto__ payload

Published Mar 11, 2020

Description

minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.

Affected products

Remediation

Red Hat statement

Red Hat Quay only includes minimist as a dependency of the test suites, and it not include it in the product. We may fix this issue in a future Red Hat Quay release.

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Mar 11, 2020
Updated Aug 4, 2024
Reserved Jan 21, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 10, 2020
ENISA EUVD
Assigner snyk
Published Mar 11, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2020-0395 GHSA-VH95-RMGR-6W4M