Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Mageia 7: MGASA-2021-0170 Moderate: Nodejs Yargs Object Prototype Attack

mageia
Calendar Grey April 2, 2021
Dist Mageia Esm H88
MGASA-2021-0171 addresses a vulnerability in nodejs-yargs that allows attackers to exploit Object attributes through harmful input.
yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload (CVE-2020-7608)

Summary

yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload (CVE-2020-7608).

References

- https://bugs.mageia.org/show_bug.cgi?id=27975

- https://www.cve.org/CVERecord?id=CVE-2020-7608

Resolution

SRPMS

- 7/core/nodejs-yargs-parser-10.0.0-3.1.mga7

Publication date: 02 Apr 2021
URL: https://advisories.mageia.org/MGASA-2021-0170.html
Type: security
CVE: CVE-2020-7608

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here