CRITICAL
Prototype Pollution
Published Oct 29, 2020
9.8
CRITICALCVSS 3.1
EPSS 4.74%
Description
This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing options (or the defaults options) are deeply merged with provided options. However, during this operation, the keys of the object being set are not checked, leading to a prototype pollution.
Affected products
- Vendor n/a Product Chart.js Defaultn/a
- Version unspecifiedStatusaffectedConstraints<2.9.4
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Chart.js | n/a |
|
No data.
RHPAM 7.13.1 async
chart.js
Fixed · RHSA-2022:6813
| Product | Package | State | Advisory |
|---|---|---|---|
| RHPAM 7.13.1 async | chart.js | Fixed | RHSA-2022:6813 |
chart.js
npm
Introduced 0 Fixed 2.9.4
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | chart.js | 0 | 2.9.4 |
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2020-7746 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2096966 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-1096 Advisory
- https://github.com/advisories/GHSA-h68q-55jf-x68w Advisory
- https://github.com/chartjs/Chart.js/pull/7920 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-7746
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1019375 x_refsource_MISCExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBCHARTJS-1019376 x_refsource_MISCExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1019374 x_refsource_MISCExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-CHARTJS-1018716 x_refsource_MISCExploitThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-7746
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-7746 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2096966 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-1096 | Advisory | |
| https://github.com/advisories/GHSA-h68q-55jf-x68w | Advisory | |
| https://github.com/chartjs/Chart.js/pull/7920 | x_refsource_MISCPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-7746 | ||
| https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1019375 | x_refsource_MISCExploitThird Party Advisory | |
| https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBCHARTJS-1019376 | x_refsource_MISCExploitThird Party Advisory | |
| https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1019374 | x_refsource_MISCExploitThird Party Advisory | |
| https://snyk.io/vuln/SNYK-JS-CHARTJS-1018716 | x_refsource_MISCExploitThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-7746 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Oct 29, 2020
Updated Sep 16, 2024
Reserved Jan 21, 2020
Link CVE-2020-7746
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2021-1096 GHSA-H68Q-55JF-X68W Assigner snyk
Published Oct 29, 2020
Updated Sep 16, 2024
Exploited since n/a
Link EUVD-2021-1096