HIGH
Prototype Pollution
Published Oct 13, 2020
7.3
HIGHCVSS 3.1
EPSS 3.92%
Description
The package mathjs before 7.5.1 are vulnerable to Prototype Pollution via the deepExtend function that runs upon configuration updates.
Affected products
- Vendor n/a Product Mathjs Defaultn/a
- Version unspecifiedStatusaffectedConstraints<7.5.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Mathjs | n/a |
|
No data.
Red Hat Ansible Tower 3.7 for RHEL 7
ansible-tower-37/ansible-tower-rhel7:3.7.4-1
Fixed · RHSA-2020:5249
Red Hat Ansible Tower 3
mathjs
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Tower 3.7 for RHEL 7 | ansible-tower-37/ansible-tower-rhel7:3.7.4-1 | Fixed | RHSA-2020:5249 |
| Red Hat Ansible Tower 3 | mathjs | Out of support scope | n/a |
mathjs
npm
Introduced 0 Fixed 7.5.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | mathjs | 0 | 7.5.1 |
Remediation
No remediation recorded yet.
Weaknesses (3)
References (14)
- https://access.redhat.com/security/cve/CVE-2020-7743 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1887999 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-1224 Advisory
- https://github.com/advisories/GHSA-x2fc-mxcx-w4mf Advisory
- https://github.com/josdejong/mathjs/blob/develop/HISTORY.md#2020-10-10-version-751
- https://github.com/josdejong/mathjs/blob/develop/src/utils/object.js%23L82 x_refsource_MISCBroken LinkThird Party Advisory
- https://github.com/josdejong/mathjs/commit/ecb80514e80bce4e6ec7e71db8ff79954f07c57e x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-7743
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1017113 x_refsource_MISCExploitMitigationThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1017112 x_refsource_MISCExploitMitigationThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1017111 x_refsource_MISCExploitMitigationThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-MATHJS-1016401 x_refsource_MISCExploitMitigationThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-7743
- https://www.npmjs.com/package/mathjs
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Oct 13, 2020
Updated Sep 16, 2024
Reserved Jan 21, 2020
Link CVE-2020-7743
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2021-1224 GHSA-X2FC-MXCX-W4MF Assigner snyk
Published Oct 13, 2020
Updated Sep 16, 2024
Exploited since n/a
Link EUVD-2021-1224