uglify-js: Prototype pollution vulnerability in function DEFNODE in ast.js
Published Oct 20, 2022
9.8
CRITICALCVSS 3.1
EPSS 1.50%
Description
Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.js. NOTE: the vendor considers this an invalid report.
Affected products
No data.
- 3.13.2
No data.
Migration Toolkit for Runtimes
uglify-js
Affected
OpenShift Service Mesh 2
openshift-service-mesh/kiali-rhel8
Will not fix
OpenShift Service Mesh 2.0
openshift-service-mesh/kiali-rhel8
Will not fix
OpenShift Service Mesh 2.0
servicemesh-grafana
Will not fix
OpenShift Service Mesh 2.0
servicemesh-prometheus
Will not fix
OpenShift Service Mesh 2.1
openshift-service-mesh/kiali-rhel8
Will not fix
OpenShift Service Mesh 2.1
servicemesh-grafana
Will not fix
Red Hat A-MQ Online
uglify-js
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/application-ui-rhel8
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/console-rhel8
Will not fix
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/grc-ui-rhel8
Not affected
Red Hat Advanced Cluster Security 3
advanced-cluster-security/rhacs-docs-rhel8
Not affected
Red Hat Advanced Cluster Security 3
advanced-cluster-security/rhacs-main-rhel8
Will not fix
Red Hat Advanced Cluster Security 3
advanced-cluster-security/rhacs-rhel8-operator
Will not fix
Red Hat Advanced Cluster Security 3
advanced-cluster-security/rhacs-roxctl-rhel8
Not affected
Red Hat Ansible Automation Platform 2
aap-azure-ui
Not affected
Red Hat Ceph Storage 4
cockpit-ceph-installer
Will not fix
Red Hat Decision Manager 7
uglify-js
Out of support scope
Red Hat Discovery 1
discovery-server-container
Not affected
Red Hat Enterprise Linux 6
firefox
Not affected
Red Hat Enterprise Linux 7
firefox
Not affected
Red Hat Enterprise Linux 8
389-ds:1.4/389-ds-base
Not affected
Red Hat Enterprise Linux 8
cockpit
Not affected
Red Hat Enterprise Linux 8
cockpit-appstream
Not affected
Red Hat Enterprise Linux 8
container-tools:rhel8/cockpit-podman
Not affected
Red Hat Enterprise Linux 8
grafana
Not affected
Red Hat Enterprise Linux 8
mozjs60
Not affected
Red Hat Enterprise Linux 8
pcs
Not affected
Red Hat Enterprise Linux 9
gjs
Not affected
Red Hat Enterprise Linux 9
grafana
Not affected
Red Hat Enterprise Linux 9
polkit
Not affected
Red Hat Fuse 7
uglify-js
Will not fix
Red Hat Integration Camel K 1
uglify-js
Will not fix
Red Hat JBoss Data Grid 7
uglify-js
Out of support scope
Red Hat OpenShift Container Platform 3.11
openshift3/ose-console
Out of support scope
Red Hat OpenShift Container Platform 4
openshift4/ose-console-rhel9
Not affected
Red Hat OpenShift Dev Spaces
devspaces-theia-rhel8-container
Not affected
Red Hat OpenShift Dev Spaces
devspaces/dashboard-rhel8
Not affected
Red Hat OpenShift GitOps
openshift-gitops-1/argocd-rhel8
Not affected
Red Hat OpenShift distributed tracing 2
rhosdt/jaeger-all-in-one-rhel8
Affected
Red Hat OpenShift distributed tracing 2
rhosdt/jaeger-query-rhel8
Affected
Red Hat Openshift Container Storage 4
ocs4/mcg-core-rhel8
Out of support scope
Red Hat Openshift Data Foundation 4
noobaa-core-container
Not affected
Red Hat Openshift Data Foundation 4
odf4/mcg-core-rhel8
Not affected
Red Hat Process Automation 7
uglify-js
Out of support scope
Red Hat Quay 3
quay/quay-rhel8
Affected
Red Hat build of Apicurio Registry 2
uglify-js
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Migration Toolkit for Runtimes | uglify-js | Affected | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/kiali-rhel8 | Will not fix | n/a |
| OpenShift Service Mesh 2.0 | openshift-service-mesh/kiali-rhel8 | Will not fix | n/a |
| OpenShift Service Mesh 2.0 | servicemesh-grafana | Will not fix | n/a |
| OpenShift Service Mesh 2.0 | servicemesh-prometheus | Will not fix | n/a |
| OpenShift Service Mesh 2.1 | openshift-service-mesh/kiali-rhel8 | Will not fix | n/a |
| OpenShift Service Mesh 2.1 | servicemesh-grafana | Will not fix | n/a |
| Red Hat A-MQ Online | uglify-js | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/application-ui-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/console-rhel8 | Will not fix | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/grc-ui-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Security 3 | advanced-cluster-security/rhacs-docs-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Security 3 | advanced-cluster-security/rhacs-main-rhel8 | Will not fix | n/a |
| Red Hat Advanced Cluster Security 3 | advanced-cluster-security/rhacs-rhel8-operator | Will not fix | n/a |
| Red Hat Advanced Cluster Security 3 | advanced-cluster-security/rhacs-roxctl-rhel8 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | aap-azure-ui | Not affected | n/a |
| Red Hat Ceph Storage 4 | cockpit-ceph-installer | Will not fix | n/a |
| Red Hat Decision Manager 7 | uglify-js | Out of support scope | n/a |
| Red Hat Discovery 1 | discovery-server-container | Not affected | n/a |
| Red Hat Enterprise Linux 6 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 7 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | 389-ds:1.4/389-ds-base | Not affected | n/a |
| Red Hat Enterprise Linux 8 | cockpit | Not affected | n/a |
| Red Hat Enterprise Linux 8 | cockpit-appstream | Not affected | n/a |
| Red Hat Enterprise Linux 8 | container-tools:rhel8/cockpit-podman | Not affected | n/a |
| Red Hat Enterprise Linux 8 | grafana | Not affected | n/a |
| Red Hat Enterprise Linux 8 | mozjs60 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | pcs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | gjs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | grafana | Not affected | n/a |
| Red Hat Enterprise Linux 9 | polkit | Not affected | n/a |
| Red Hat Fuse 7 | uglify-js | Will not fix | n/a |
| Red Hat Integration Camel K 1 | uglify-js | Will not fix | n/a |
| Red Hat JBoss Data Grid 7 | uglify-js | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift3/ose-console | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-console-rhel9 | Not affected | n/a |
| Red Hat OpenShift Dev Spaces | devspaces-theia-rhel8-container | Not affected | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/dashboard-rhel8 | Not affected | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/argocd-rhel8 | Not affected | n/a |
| Red Hat OpenShift distributed tracing 2 | rhosdt/jaeger-all-in-one-rhel8 | Affected | n/a |
| Red Hat OpenShift distributed tracing 2 | rhosdt/jaeger-query-rhel8 | Affected | n/a |
| Red Hat Openshift Container Storage 4 | ocs4/mcg-core-rhel8 | Out of support scope | n/a |
| Red Hat Openshift Data Foundation 4 | noobaa-core-container | Not affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/mcg-core-rhel8 | Not affected | n/a |
| Red Hat Process Automation 7 | uglify-js | Out of support scope | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Affected | n/a |
| Red Hat build of Apicurio Registry 2 | uglify-js | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
OpenShift Service Mesh is closed as wontfix, as @types/uglify-js is hoisted from the storybook, which is a dev dep only and does not affect the production Kiali container. Also, this dependency has been removed completely from OSSM 2.3. Upstream doesn't consider this as a vulnerability. Refer to the "External References" section for more details.
References (10)
- https://access.redhat.com/security/cve/CVE-2022-37598 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2142469 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-40223 Advisory
- https://github.com/mishoo/UglifyJS/blob/352a944868b09c9ce3121a49d4a0bf0afe370a35/lib/ast.js#L46 ExploitThird Party Advisory
- https://github.com/mishoo/UglifyJS/blob/352a944868b09c9ce3121a49d4a0bf0afe370a35/lib/ast.js#L79 ExploitThird Party Advisory
- https://github.com/mishoo/UglifyJS/issues/5699 Issue TrackingThird Party Advisory
- https://github.com/mishoo/UglifyJS/issues/5699#issuecomment-1315927228
- https://github.com/mishoo/UglifyJS/issues/5721#issuecomment-1292849604 Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-37598
- https://www.cve.org/CVERecord?id=CVE-2022-37598
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-37598 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2142469 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-40223 | Advisory | |
| https://github.com/mishoo/UglifyJS/blob/352a944868b09c9ce3121a49d4a0bf0afe370a35/lib/ast.js#L46 | ExploitThird Party Advisory | |
| https://github.com/mishoo/UglifyJS/blob/352a944868b09c9ce3121a49d4a0bf0afe370a35/lib/ast.js#L79 | ExploitThird Party Advisory | |
| https://github.com/mishoo/UglifyJS/issues/5699 | Issue TrackingThird Party Advisory | |
| https://github.com/mishoo/UglifyJS/issues/5699#issuecomment-1315927228 | ||
| https://github.com/mishoo/UglifyJS/issues/5721#issuecomment-1292849604 | Third Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-37598 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-37598 |
Change history (0)
No recorded changes yet.