HIGH
Prototype Pollution
Published Dec 11, 2020
7.5
HIGHCVSS 3.1
EPSS 2.15%
Description
This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn 'mixes objects into the target object, recursively mixing existing child objects as well'. In both cases, the key used to access the target object recursively is not checked, leading to a Prototype Pollution.
Affected products
- Vendor n/a Product Mout Defaultunknown
Affected
- ≥ 0, < unspecified
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Mout | unknown | Affected
|
No data.
No Red Hat product state for this CVE.
mout
npm
Introduced 0 Fixed 1.2.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | mout | 0 | 1.2.3 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1121 Advisory
- https://github.com/advisories/GHSA-pc58-wgmc-hfjr Advisory
- https://github.com/mout/mout/blob/master/src/object/deepFillIn.js x_refsource_MISCExploitThird Party Advisory
- https://github.com/mout/mout/blob/master/src/object/deepMixIn.js x_refsource_MISCExploitThird Party Advisory
- https://github.com/mout/mout/commit/3fecf1333e6d71ae72edf48c71dc665e40df7605
- https://nvd.nist.gov/vuln/detail/CVE-2020-7792
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1050374 x_refsource_MISCExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1050373 x_refsource_MISCExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-MOUT-1014544 x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1121 | Advisory | |
| https://github.com/advisories/GHSA-pc58-wgmc-hfjr | Advisory | |
| https://github.com/mout/mout/blob/master/src/object/deepFillIn.js | x_refsource_MISCExploitThird Party Advisory | |
| https://github.com/mout/mout/blob/master/src/object/deepMixIn.js | x_refsource_MISCExploitThird Party Advisory | |
| https://github.com/mout/mout/commit/3fecf1333e6d71ae72edf48c71dc665e40df7605 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2020-7792 | ||
| https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1050374 | x_refsource_MISCExploitThird Party Advisory | |
| https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1050373 | x_refsource_MISCExploitThird Party Advisory | |
| https://snyk.io/vuln/SNYK-JS-MOUT-1014544 | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Dec 11, 2020
Updated Sep 17, 2024
Reserved Jan 21, 2020
Link CVE-2020-7792
CISA Vulnrichment
No data
Red Hat
No data
GitHub
Link GHSA-PC58-WGMC-HFJR