CVE-2018-3719
published 2018-06-07CVE-2018-3719: mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the…
PriorityP346high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.12%
80.0th percentile
mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-mixin-deep | < node-mixin-deep 1.1.3-2 (bookworm) | node-mixin-deep 1.1.3-2 (bookworm) |
| hackerone | mixin-deep_node_module | — | — |
| mixin-deep_project | mixin-deep | < 1.3.1 | 1.3.1 |
| mixin-deep_project | mixin-deep | >= 0 < 1.3.1 | 1.3.1 |
| mutt | mutt | >= 0 < 1.5.24-1ubuntu0.2 | 1.5.24-1ubuntu0.2 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
nodejs-mixin-deep: Prototype pollution via merging functions
vendor_redhat·2018-04-25·CVSS 8.8
CVE-2018-3719 [HIGH] CWE-471 nodejs-mixin-deep: Prototype pollution via merging functions
nodejs-mixin-deep: Prototype pollution via merging functions
mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
Statement: In Red Hat OpenShift Logging the openshift-logging/kibana6-rhel8 container bundles many nodejs packages as a build time dependencies, including the mixin-deep package.
The vulnerable code is not used hence the impact to OpenShift Logging by this vulnerability is Low.
Package: openshift-logging/kibana6-rhel8 (Logging Subsystem for Red Hat OpenShift) - Not affected
Debian
CVE-2018-3719: node-mixin-deep - mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immut...
vendor_debian·2018·CVSS 8.8
CVE-2018-3719 [HIGH] CVE-2018-3719: node-mixin-deep - mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immut...
mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
Scope: local
bookworm: resolved (fixed in 1.1.3-2)
bullseye: resolved (fixed in 1.1.3-2)
forky: resolved (fixed in 1.1.3-2)
sid: resolved (fixed in 1.1.3-2)
trixie: resolved (fixed in 1.1.3-2)
OSV
mutt vulnerabilities
osv·2018-09-28·CVSS 9.8
CVE-2018-14350 mutt vulnerabilities
mutt vulnerabilities
USN-3719-1 fixed vulnerabilities in Mutt. Unfortunately, the fixes were
not correctly applied to the packaging for Mutt in Ubuntu 16.04 LTS.
This update corrects the oversight.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Mutt incorrectly handled certain requests.
An attacker could possibly use this to execute arbitrary code.
(CVE-2018-14350, CVE-2018-14352, CVE-2018-14354, CVE-2018-14359,
CVE-2018-14358, CVE-2018-14353 ,CVE-2018-14357)
It was discovered that Mutt incorrectly handled certain inputs.
An attacker could possibly use this to access or expose sensitive
information. (CVE-2018-14355, CVE-2018-14356, CVE-2018-14351,
CVE-2018-14362, CVE-2018-14349)
OSV
Prototype Pollution in mixin-deep
osv·2018-07-26
CVE-2018-3719 [HIGH] Prototype Pollution in mixin-deep
Prototype Pollution in mixin-deep
Versions of `mixin-deep` before 1.3.1 are vulnerable to prototype pollution via merging functions.
## Recommendation
Update to version 1.3.1 or later.
GHSA
Prototype Pollution in mixin-deep
ghsa·2018-07-26
CVE-2018-3719 [HIGH] CWE-20 Prototype Pollution in mixin-deep
Prototype Pollution in mixin-deep
Versions of `mixin-deep` before 1.3.1 are vulnerable to prototype pollution via merging functions.
## Recommendation
Update to version 1.3.1 or later.
OSV
CVE-2018-3719: mixin-deep node module before 1
osv·2018-06-07·CVSS 8.8
CVE-2018-3719 [HIGH] CVE-2018-3719: mixin-deep node module before 1
mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-3719 nodejs-mixin-deep: Prototype pollution via merging functions [fedora-28]
bugzilla·2018-05-10·CVSS 8.8
CVE-2018-3719 [HIGH] CVE-2018-3719 nodejs-mixin-deep: Prototype pollution via merging functions [fedora-28]
CVE-2018-3719 nodejs-mixin-deep: Prototype pollution via merging functions [fedora-28]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-28.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to f
Bugzilla
CVE-2018-3719 nodejs-mixin-deep: Prototype pollution via merging functions
bugzilla·2018-05-10·CVSS 8.8
CVE-2018-3719 [HIGH] CVE-2018-3719 nodejs-mixin-deep: Prototype pollution via merging functions
CVE-2018-3719 nodejs-mixin-deep: Prototype pollution via merging functions
Versions of mixin-deep before 1.3.1 are vulnerable to prototype pollution via merging functions.
External References:
https://nodesecurity.io/advisories/578
https://hackerone.com/reports/311236
Discussion:
Created nodejs-mixin-deep tracking bugs for this issue:
Affects: fedora-28 [bug 1576649]
---
This issue has been addressed in Rawhide with an upgrade to version 1.3.1, and an update has been proposed for F28: https://bodhi.fedoraproject.org/updates/FEDORA-2018-ab62814cee
---
ARRAY(0x55ab81ab9018)
2018-06-07
Published