npm-serialize-javascript: allows remote attackers to inject arbitrary code via the function deleteFunctions within index.js
Published Jun 1, 2020
8.1
HIGHCVSS 3.1
EPSS 3.01%
Description
serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js".
Affected products
- Vendor n/a Product Serialize-Javascript Defaultn/a
- Version All versions prior to version 3.1.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Serialize-Javascript | n/a |
|
- < 3.1.0
No data.
OpenShift Service Mesh 1.0
servicemesh-grafana-0:6.2.2-38.el8
Fixed · RHSA-2020:2861
OpenShift Service Mesh 1.1
servicemesh-grafana-0:6.4.3-11.el8
Fixed · RHSA-2020:2796
Logging Subsystem for Red Hat OpenShift
openshift-logging/kibana6-rhel8
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-grafana
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-prometheus
Fix deferred
Red Hat OpenShift Virtualization 1
kubevirt-web-ui-container
Will not fix
Red Hat OpenShift Virtualization 2
kubevirt-web-ui-container
Not affected
Red Hat OpenShift distributed tracing 2
rhosdt/jaeger-all-in-one-rhel8
Fix deferred
Red Hat Quay 3
nodejs-serialize-javascript
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Service Mesh 1.0 | servicemesh-grafana-0:6.2.2-38.el8 | Fixed | RHSA-2020:2861 |
| OpenShift Service Mesh 1.1 | servicemesh-grafana-0:6.4.3-11.el8 | Fixed | RHSA-2020:2796 |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-grafana | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-prometheus | Fix deferred | n/a |
| Red Hat OpenShift Virtualization 1 | kubevirt-web-ui-container | Will not fix | n/a |
| Red Hat OpenShift Virtualization 2 | kubevirt-web-ui-container | Not affected | n/a |
| Red Hat OpenShift distributed tracing 2 | rhosdt/jaeger-all-in-one-rhel8 | Fix deferred | n/a |
| Red Hat Quay 3 | nodejs-serialize-javascript | Fix deferred | n/a |
serialize-javascript
npm
Introduced 0 Fixed 3.1.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | serialize-javascript | 0 | 3.1.0 |
Remediation
Red Hat statement
Red Hat Quay includes serialize-javascript as a dependency of webpack which is only used at build time. The vulnerable library is not used at runtime meaning this has a low impact on Red Hat Quay. The currently supported versions of Container Native Virtualization 2 are not affected by this flaw. However, version 2.0, which is no longer supported, is affected. In OpenShift distributed tracing there is bundled vulnerable version of the serialize-javascript Nodejs package, however access to the vulnerable function is restricted and protected by OpenShift OAuth, hence the impact by this vulnerability is reduced to Low. In Red Hat OpenShift Logging the openshift-logging/kibana6-rhel8 container bundles many nodejs packages as a build time dependencies, including the serialize-javascript package. The vulnerable code is not used hence the impact to OpenShift Logging by this vulnerability is Low.
References (7)
- https://access.redhat.com/security/cve/CVE-2020-7660 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1844228 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-0628 Advisory
- https://github.com/advisories/GHSA-hxcc-f52p-wc94 Advisory
- https://github.com/yahoo/serialize-javascript/commit/f21a6fb3ace2353413761e79717b2d210ba6ccbd x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-7660
- https://www.cve.org/CVERecord?id=CVE-2020-7660
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-7660 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1844228 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-0628 | Advisory | |
| https://github.com/advisories/GHSA-hxcc-f52p-wc94 | Advisory | |
| https://github.com/yahoo/serialize-javascript/commit/f21a6fb3ace2353413761e79717b2d210ba6ccbd | x_refsource_MISCPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-7660 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-7660 |
Change history (0)
No recorded changes yet.