Prototype Pollution in immerjs/immer
Published Sep 2, 2021
9.8
CRITICALCVSS 3.1
EPSS 1.65%
Description
immer is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Affected products
-
- Version unspecifiedStatusaffectedConstraints<=9.0.5
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Immerjs | Immerjs/immer | n/a |
|
- ≤ 9.0.5
No data.
Red Hat Migration Toolkit for Containers 1.5
rhmtc/openshift-migration-ui-rhel8:v1.5.2-6
Fixed · RHSA-2021:4848
OpenShift Service Mesh 1
servicemesh-grafana
Out of support scope
OpenShift Service Mesh 1
servicemesh-prometheus
Out of support scope
OpenShift Service Mesh 2.0
servicemesh-grafana
Affected
OpenShift Service Mesh 2.0
servicemesh-prometheus
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/console-rhel8
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/kui-web-terminal-rhel8
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/search-ui-rhel8
Affected
Red Hat OpenShift Container Platform 4
openshift4/ose-grafana
Fix deferred
Red Hat OpenShift Container Platform 4
openshift4/ose-prometheus
Fix deferred
Red Hat OpenShift Container Platform 4
openshift4/ose-thanos-rhel8
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Migration Toolkit for Containers 1.5 | rhmtc/openshift-migration-ui-rhel8:v1.5.2-6 | Fixed | RHSA-2021:4848 |
| OpenShift Service Mesh 1 | servicemesh-grafana | Out of support scope | n/a |
| OpenShift Service Mesh 1 | servicemesh-prometheus | Out of support scope | n/a |
| OpenShift Service Mesh 2.0 | servicemesh-grafana | Affected | n/a |
| OpenShift Service Mesh 2.0 | servicemesh-prometheus | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/console-rhel8 | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/kui-web-terminal-rhel8 | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/search-ui-rhel8 | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-grafana | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-prometheus | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-thanos-rhel8 | Fix deferred | n/a |
immer
npm
Introduced 7.0.0 Fixed 9.0.6
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | immer | 7.0.0 | 9.0.6 |
Remediation
Red Hat statement
In OpenShift Container Platform (OCP) and OpenShift Migration Toolkit for Containers (MTC), the affected components are behind OpenShift OAuth authentication. This restricts access to the vulnerable nodejs-immer library to authenticated users only, therefore the impact is Low.
References (8)
- https://access.redhat.com/security/cve/CVE-2021-3757 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2000734 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-2031 Advisory
- https://github.com/advisories/GHSA-c36v-fmgq-m8hx Advisory
- https://github.com/immerjs/immer/commit/fa671e55ee9bd42ae08cc239102b665a23958237 x_refsource_MISCPatchThird Party Advisory
- https://huntr.dev/bounties/23d38099-71cd-42ed-a77a-71e68094adfa x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-3757
- https://www.cve.org/CVERecord?id=CVE-2021-3757
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2021-3757 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2000734 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-2031 | Advisory | |
| https://github.com/advisories/GHSA-c36v-fmgq-m8hx | Advisory | |
| https://github.com/immerjs/immer/commit/fa671e55ee9bd42ae08cc239102b665a23958237 | x_refsource_MISCPatchThird Party Advisory | |
| https://huntr.dev/bounties/23d38099-71cd-42ed-a77a-71e68094adfa | x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2021-3757 | ||
| https://www.cve.org/CVERecord?id=CVE-2021-3757 |
Change history (0)
No recorded changes yet.