Prototype Pollution
Published Sep 1, 2020
9.8
CRITICALCVSS 3.1
EPSS 3.19%
Description
The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.
Affected products
- Vendor n/a Product Node-Forge Defaultunknown
Affected
- ≥ 0, < unspecified
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Node-Forge | unknown | Affected
|
- < 0.10.0
No data.
Red Hat Ansible Tower 3.7 for RHEL 7
ansible-tower-37/ansible-tower-rhel7:3.7.4-1
Fixed · RHSA-2020:5249
Red Hat OpenShift Container Storage 4.6.0 on RHEL-8
ocs4/mcg-core-rhel8:5.6.0-38.31e0c3c7b.5.6
Fixed · RHSA-2020:5605
Red Hat OpenShift Container Platform 4
openshift4/ose-prometheus
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Tower 3.7 for RHEL 7 | ansible-tower-37/ansible-tower-rhel7:3.7.4-1 | Fixed | RHSA-2020:5249 |
| Red Hat OpenShift Container Storage 4.6.0 on RHEL-8 | ocs4/mcg-core-rhel8:5.6.0-38.31e0c3c7b.5.6 | Fixed | RHSA-2020:5605 |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-prometheus | Not affected | n/a |
node-forge
npm
Introduced 0 Fixed 0.10.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | node-forge | 0 | 0.10.0 |
Remediation
Red Hat statement
In Red Hat Openshift Container Storage 4 the noobaa-core container includes the affected version of node-forge as a dependency of google-p12-pem, however the vulnerable function `util.setPath` is not being used and hence this issue has been rated as having a security impact of Low. In OpenShift Container Platform (OCP) the prometheus container is behind OpenShift OAuth restricting access to the vulnerable node-forge library to authenticated users only, therefore the impact is Low.
References (11)
- https://access.redhat.com/security/cve/CVE-2020-7720 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1874606 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-0922 Advisory
- https://github.com/advisories/GHSA-92xj-mqp7-vmcj Advisory
- https://github.com/digitalbazaar/forge/blob/master/CHANGELOG.md x_refsource_CONFIRMRelease NotesThird Party Advisory
- https://github.com/digitalbazaar/forge/blob/master/CHANGELOG.md#removed
- https://github.com/digitalbazaar/forge/commit/6a1e3ef74f6eb345bcff1b82184201d1e28b6756
- https://nvd.nist.gov/vuln/detail/CVE-2020-7720
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-609293 x_refsource_MISCExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-NODEFORGE-598677 x_refsource_MISCExploitThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-7720
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-7720 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1874606 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-0922 | Advisory | |
| https://github.com/advisories/GHSA-92xj-mqp7-vmcj | Advisory | |
| https://github.com/digitalbazaar/forge/blob/master/CHANGELOG.md | x_refsource_CONFIRMRelease NotesThird Party Advisory | |
| https://github.com/digitalbazaar/forge/blob/master/CHANGELOG.md#removed | ||
| https://github.com/digitalbazaar/forge/commit/6a1e3ef74f6eb345bcff1b82184201d1e28b6756 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2020-7720 | ||
| https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-609293 | x_refsource_MISCExploitThird Party Advisory | |
| https://snyk.io/vuln/SNYK-JS-NODEFORGE-598677 | x_refsource_MISCExploitThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-7720 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub