HIGH
nodejs-json-bigint: Prototype pollution via `__proto__` assignment could result in DoS
Published Sep 18, 2020
7.5
HIGHCVSS 3.1
EPSS 1.71%
Description
Prototype pollution in json-bigint npm package < 1.0.0 may lead to a denial-of-service (DoS) attack.
Affected products
- Vendor n/a Product Json-Bigint Defaultn/a
- Version Fixed in version 1.0.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Json-Bigint | n/a |
|
- < 1.0.0
No data.
Red Hat OpenShift Container Storage 4.6.0 on RHEL-8
ocs4/mcg-core-rhel8:5.6.0-38.31e0c3c7b.5.6
Fixed · RHSA-2020:5605
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Storage 4.6.0 on RHEL-8 | ocs4/mcg-core-rhel8:5.6.0-38.31e0c3c7b.5.6 | Fixed | RHSA-2020:5605 |
json-bigint
npm
Introduced 0 Fixed 1.0.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | json-bigint | 0 | 1.0.0 |
Remediation
Red Hat statement
In Red Hat Openshift Container Storage 4 the noobaa-core container includes the affected version of json-bigint as a dependency of googleapis, however the json-bigint library is not being used and hence this issue has been rated as having a security impact of Low.
Weaknesses (1)
References (6)
- https://access.redhat.com/security/cve/CVE-2020-8237 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1881028 Issue Tracking
- https://github.com/advisories/GHSA-wgfq-7857-4jcc Advisory
- https://hackerone.com/reports/916430 x_refsource_MISCExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-8237
- https://www.cve.org/CVERecord?id=CVE-2020-8237
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-8237 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1881028 | Issue Tracking | |
| https://github.com/advisories/GHSA-wgfq-7857-4jcc | Advisory | |
| https://hackerone.com/reports/916430 | x_refsource_MISCExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-8237 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-8237 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Sep 18, 2020
Updated Aug 4, 2024
Reserved Jan 28, 2020
Link CVE-2020-8237
CISA Vulnrichment
GHSA-WGFQ-7857-4JCC Updated n/a