Back

CRITICAL

uglify-js: Prototype pollution vulnerability in function DEFNODE in ast.js

Published Oct 20, 2022

Description

Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.js. NOTE: the vendor considers this an invalid report.

Affected products

Remediation

Red Hat statement

OpenShift Service Mesh is closed as wontfix, as @types/uglify-js is hoisted from the storybook, which is a dev dep only and does not affect the production Kiali container. Also, this dependency has been removed completely from OSSM 2.3. Upstream doesn't consider this as a vulnerability. Refer to the "External References" section for more details.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 20, 2022
Updated Aug 3, 2024
Reserved Aug 8, 2022
CISA Vulnrichment
Updated May 1, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 20, 2022
ENISA EUVD
Assigner mitre
Published Oct 20, 2022
Updated Aug 3, 2024
Exploited since n/a
EUVD-2022-40223