Back

HIGH

npm-serialize-javascript: allows remote attackers to inject arbitrary code via the function deleteFunctions within index.js

Published Jun 1, 2020

Description

serialize-javascript prior to 3.1.0 allows remote attackers to inject arbitrary code via the function "deleteFunctions" within "index.js".

Affected products

Remediation

Red Hat statement

Red Hat Quay includes serialize-javascript as a dependency of webpack which is only used at build time. The vulnerable library is not used at runtime meaning this has a low impact on Red Hat Quay. The currently supported versions of Container Native Virtualization 2 are not affected by this flaw. However, version 2.0, which is no longer supported, is affected. In OpenShift distributed tracing there is bundled vulnerable version of the serialize-javascript Nodejs package, however access to the vulnerable function is restricted and protected by OpenShift OAuth, hence the impact by this vulnerability is reduced to Low. In Red Hat OpenShift Logging the openshift-logging/kibana6-rhel8 container bundles many nodejs packages as a build time dependencies, including the serialize-javascript package. The vulnerable code is not used hence the impact to OpenShift Logging by this vulnerability is Low.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Jun 1, 2020
Updated Aug 4, 2024
Reserved Jan 21, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Apr 1, 2020
ENISA EUVD
Assigner snyk
Published Jun 1, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2020-0628 GHSA-HXCC-F52P-WC94