Back

HIGH

nodejs-json-bigint: Prototype pollution via `__proto__` assignment could result in DoS

Published Sep 18, 2020

Description

Prototype pollution in json-bigint npm package < 1.0.0 may lead to a denial-of-service (DoS) attack.

Affected products

Remediation

Red Hat statement

In Red Hat Openshift Container Storage 4 the noobaa-core container includes the affected version of json-bigint as a dependency of googleapis, however the json-bigint library is not being used and hence this issue has been rated as having a security impact of Low.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Sep 18, 2020
Updated Aug 4, 2024
Reserved Jan 28, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 26, 2020
GHSA-WGFQ-7857-4JCC