Prototype Pollution
Published Nov 17, 2020
9.8
CRITICALCVSS 3.1
EPSS 69.38%
Description
The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.
Affected products
- Vendor n/a Product Y18n Defaultn/a
- Version unspecifiedStatusaffectedConstraints<5.0.5
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Y18n | n/a |
|
Configuration 1
- < 3.2.2
- ≥ 5.0.0 · < 5.0.5
- 4.0.0
Configuration 2
Configuration 3
- < 1.0.1.1
No data.
Red Hat Enterprise Linux 8
nodejs:10-8030020210118191659.229f0a1c
Fixed · RHSA-2021:0548
Red Hat Enterprise Linux 8
nodejs:12-8030020201124152102.229f0a1c
Fixed · RHSA-2020:5499
Red Hat Enterprise Linux 8
nodejs:14-8030020210126165503.229f0a1c
Fixed · RHSA-2021:0551
Red Hat OpenShift Container Platform 4.7
openshift4/ose-grafana:v4.7.0-202102130115.p0
Fixed · RHSA-2020:5633
Red Hat OpenShift Container Platform 4.8
openshift4/ose-thanos-rhel8:v4.8.0-202106291913.p0.git.c358e96.assembly.stream
Fixed · RHSA-2021:2438
Red Hat OpenShift Container Storage 4.7.0 on RHEL-8
ocs4/mcg-core-rhel8:5.7.0-60.2c1fdb0.5.7
Fixed · RHSA-2021:2041
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs10-nodejs-0:10.23.1-2.el7
Fixed · RHSA-2021:0521
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs12-nodejs-0:12.19.1-2.el7
Fixed · RHSA-2020:5305
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs14-nodejs-0:14.15.4-2.el7
Fixed · RHSA-2021:0421
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs10-nodejs-0:10.23.1-2.el7
Fixed · RHSA-2021:0521
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs12-nodejs-0:12.19.1-2.el7
Fixed · RHSA-2020:5305
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs14-nodejs-0:14.15.4-2.el7
Fixed · RHSA-2021:0421
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs10-nodejs-0:10.23.1-2.el7
Fixed · RHSA-2021:0521
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs12-nodejs-0:12.19.1-2.el7
Fixed · RHSA-2020:5305
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs14-nodejs-0:14.15.4-2.el7
Fixed · RHSA-2021:0421
Logging Subsystem for Red Hat OpenShift
openshift-logging/kibana6-rhel8
Not affected
OpenShift Service Mesh 1
kiali
Affected
OpenShift Service Mesh 1
servicemesh-grafana
Fix deferred
OpenShift Service Mesh 2.0
kiali
Not affected
OpenShift Service Mesh 2.0
servicemesh-grafana
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
y18n
Affected
Red Hat OpenShift Container Platform 3.11
openshift3/ose-console
Fix deferred
Red Hat OpenShift Container Platform 4
openshift4/ose-console-rhel9
Fix deferred
Red Hat OpenShift Container Platform 4
openshift4/ose-prometheus
Fix deferred
Red Hat OpenShift distributed tracing 2
rhosdt/jaeger-all-in-one-rhel8
Not affected
Red Hat Openshift Data Foundation 4
noobaa-core-container
Affected
Red Hat Openshift Data Foundation 4
odf4/mcg-core-rhel8
Affected
Red Hat Openshift Data Foundation 4
odf4/odf-console-rhel9
Fix deferred
Red Hat Openshift Data Foundation 4
odf4/odf-multicluster-console-rhel9
Fix deferred
Red Hat Quay 3
quay
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | nodejs:10-8030020210118191659.229f0a1c | Fixed | RHSA-2021:0548 |
| Red Hat Enterprise Linux 8 | nodejs:12-8030020201124152102.229f0a1c | Fixed | RHSA-2020:5499 |
| Red Hat Enterprise Linux 8 | nodejs:14-8030020210126165503.229f0a1c | Fixed | RHSA-2021:0551 |
| Red Hat OpenShift Container Platform 4.7 | openshift4/ose-grafana:v4.7.0-202102130115.p0 | Fixed | RHSA-2020:5633 |
| Red Hat OpenShift Container Platform 4.8 | openshift4/ose-thanos-rhel8:v4.8.0-202106291913.p0.git.c358e96.assembly.stream | Fixed | RHSA-2021:2438 |
| Red Hat OpenShift Container Storage 4.7.0 on RHEL-8 | ocs4/mcg-core-rhel8:5.7.0-60.2c1fdb0.5.7 | Fixed | RHSA-2021:2041 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs10-nodejs-0:10.23.1-2.el7 | Fixed | RHSA-2021:0521 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs12-nodejs-0:12.19.1-2.el7 | Fixed | RHSA-2020:5305 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs14-nodejs-0:14.15.4-2.el7 | Fixed | RHSA-2021:0421 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs10-nodejs-0:10.23.1-2.el7 | Fixed | RHSA-2021:0521 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs12-nodejs-0:12.19.1-2.el7 | Fixed | RHSA-2020:5305 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs14-nodejs-0:14.15.4-2.el7 | Fixed | RHSA-2021:0421 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs10-nodejs-0:10.23.1-2.el7 | Fixed | RHSA-2021:0521 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs12-nodejs-0:12.19.1-2.el7 | Fixed | RHSA-2020:5305 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs14-nodejs-0:14.15.4-2.el7 | Fixed | RHSA-2021:0421 |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Not affected | n/a |
| OpenShift Service Mesh 1 | kiali | Affected | n/a |
| OpenShift Service Mesh 1 | servicemesh-grafana | Fix deferred | n/a |
| OpenShift Service Mesh 2.0 | kiali | Not affected | n/a |
| OpenShift Service Mesh 2.0 | servicemesh-grafana | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | y18n | Affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift3/ose-console | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-console-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-prometheus | Fix deferred | n/a |
| Red Hat OpenShift distributed tracing 2 | rhosdt/jaeger-all-in-one-rhel8 | Not affected | n/a |
| Red Hat Openshift Data Foundation 4 | noobaa-core-container | Affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/mcg-core-rhel8 | Affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/odf-console-rhel9 | Fix deferred | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/odf-multicluster-console-rhel9 | Fix deferred | n/a |
| Red Hat Quay 3 | quay | Will not fix | n/a |
y18n
npm
Introduced 0 Fixed 3.2.2y18n
npm
Introduced 4.0.0 Fixed 4.0.1y18n
npm
Introduced 5.0.0 Fixed 5.0.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | y18n | 0 | 3.2.2 |
| npm | y18n | 4.0.0 | 4.0.1 |
| npm | y18n | 5.0.0 | 5.0.5 |
Remediation
Red Hat statement
In OpenShift Container Platform (OCP), OpenShift ServiceMesh (OSSM) and OpenShift distributed tracing the affected components are behind OpenShift OAuth authentication. This restricts access to the vulnerable nodejs-y18n library to authenticated users only, therefore the impact is Low. In Red Hat OpenShift Container Storage 4 the noobaa-core container includes the affected version of y18n as a dependency of yargs. However, no unsafe usage found where the module accepts untrusted input and hence this issue has been rated as having a security impact of Low.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
2 other sources (GHSA, CVE.org) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2021-2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (28 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 69.38% (0.69377) | 99.34th | v5 (v2026.06.15) |
| Jun 15, 2026 | 68.56% (0.68558) | 99.25th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.86% (0.00860) | 74.31th | v4 (v2025.03.14) |
| Nov 18, 2025 | 5.39% (0.05388) | 89.13th | v4 (v2025.03.14) |
| Mar 30, 2025 | 0.68% (0.00676) | 69.12th | v4 (v2025.03.14) |
| Mar 29, 2025 | 1.96% (0.01960) | 72.60th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.68% (0.00676) | 69.80th | v4 (v2025.03.14) |
| Dec 17, 2024 | 7.77% (0.07773) | 94.19th | v3 (v2023.03.01) |
| Dec 12, 2024 | 27.67% (0.27668) | 96.98th | v3 (v2023.03.01) |
| Oct 8, 2024 | 28.24% (0.28236) | 96.92th | v3 (v2023.03.01) |
| Sep 21, 2024 | 33.81% (0.33806) | 97.14th | v3 (v2023.03.01) |
| Aug 4, 2024 | 26.94% (0.26941) | 96.79th | v3 (v2023.03.01) |
| May 9, 2024 | 30.43% (0.30429) | 96.91th | v3 (v2023.03.01) |
| Oct 24, 2023 | 37.66% (0.37658) | 96.75th | v3 (v2023.03.01) |
| Aug 3, 2023 | 44.33% (0.44329) | 96.88th | v3 (v2023.03.01) |
| Jul 8, 2023 | 41.63% (0.41632) | 96.80th | v3 (v2023.03.01) |
| Jun 24, 2023 | 42.45% (0.42445) | 96.81th | v3 (v2023.03.01) |
| Mar 7, 2023 | 45.47% (0.45473) | 96.80th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.11% (0.01108) | 55.18th | v2 (v2022.01.01) |
| Sep 17, 2022 | 1.11% (0.01108) | 53.57th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.11% (0.01108) | 51.54th | v2 (v2022.01.01) |
| Mar 9, 2022 | 8.93% (0.08934) | 83.26th | v2 (v2022.01.01) |
| Feb 4, 2022 | 7.18% (0.07176) | 80.33th | v2 (v2022.01.01) |
| Feb 3, 2022 | 5.36% (0.05363) | 79.74th | v1 |
| Jan 6, 2022 | 5.36% (0.05363) | 79.54th | v1 |
| Sep 1, 2021 | 1.25% (0.01247) | 68.62th | v1 |
| Jun 15, 2021 | 1.25% (0.01247) | 0.00th | v1 |
| Apr 14, 2021 | 1.04% (0.01040) | 0.00th | v1 |
References (13)
- https://access.redhat.com/security/cve/CVE-2020-7774 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1898680 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf PatchThird Party Advisory
- https://github.com/advisories/GHSA-c4w7-xm78-47vh Advisory
- https://github.com/yargs/y18n/commit/90401eea9062ad498f4f792e3fff8008c4c193a3
- https://github.com/yargs/y18n/commit/a9ac604abf756dec9687be3843e2c93bfe581f25
- https://github.com/yargs/y18n/issues/96 ExploitThird Party Advisory
- https://github.com/yargs/y18n/pull/108 PatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-7774
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1038306 ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-Y18N-1021887 ExploitThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-7774
- https://www.oracle.com/security-alerts/cpuApr2021.html PatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-7774 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1898680 | Issue Tracking | |
| https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf | PatchThird Party Advisory | |
| https://github.com/advisories/GHSA-c4w7-xm78-47vh | Advisory | |
| https://github.com/yargs/y18n/commit/90401eea9062ad498f4f792e3fff8008c4c193a3 | ||
| https://github.com/yargs/y18n/commit/a9ac604abf756dec9687be3843e2c93bfe581f25 | ||
| https://github.com/yargs/y18n/issues/96 | ExploitThird Party Advisory | |
| https://github.com/yargs/y18n/pull/108 | PatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-7774 | ||
| https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1038306 | ExploitThird Party Advisory | |
| https://snyk.io/vuln/SNYK-JS-Y18N-1021887 | ExploitThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-7774 | ||
| https://www.oracle.com/security-alerts/cpuApr2021.html | PatchThird Party Advisory |
Change history (0)
No recorded changes yet.