CVE-2019-10768
published 2019-11-19CVE-2019-10768: In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
2.18%
80.3th percentile
In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| angular | angular | >= 0 < 1.7.9 | 1.7.9 |
| angularjs | angularjs | < 1.7.9 | 1.7.9 |
| angularjs | angularjs | — | — |
| debian | angular.js | < angular.js 1.7.9-1 (bookworm) | angular.js 1.7.9-1 (bookworm) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
OSIsoft PI System (Update A)
cisa_ics·2020-05-12·CVSS 7.8
[HIGH] OSIsoft PI System (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
OSIsoft PI System (Update A)
Last RevisedJuly 27, 2020
Alert CodeICSA-20-133-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: OSIsoft
- Equipment: PI System
- Vulnerabilities: Uncontrolled Search Path Element, Improper Verification of Cryptographic Signature, Incorrect Default Permissions, Uncaught Exception, Null Pointer Dereference, Improper Input Validation, Cross-site Scripting, Insertion of Sensitive Information into Log File
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original adv
Red Hat
AngularJS: Prototype pollution in merge function could result in code injection
vendor_redhat·2019-11-07·CVSS 7.5
CVE-2019-10768 [HIGH] CWE-94 AngularJS: Prototype pollution in merge function could result in code injection
AngularJS: Prototype pollution in merge function could result in code injection
In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.
A prototype pollution vulnerability was found in AngularJS. A remote attacker could abuse this flaw by providing malicious input to the merge() function by overriding or adding properties of the Object.prototype, allowing possible injection of code.
Statement: Whilst servicemesh-grafana, and grafana-container both include a vulnerable version of angular.js (v1.6.6) the impact is lowered due to Grafana not directly implementing the angular.merge function.
Quay does not contain the affected vulnerable code pattern.
Package: servicemesh-grafana (OpenShift Serv
Debian
CVE-2019-10768: angular.js - In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or...
vendor_debian·2019·CVSS 7.5
CVE-2019-10768 [HIGH] CVE-2019-10768: angular.js - In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or...
In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.
Scope: local
bookworm: resolved (fixed in 1.7.9-1)
bullseye: resolved (fixed in 1.7.9-1)
forky: resolved (fixed in 1.7.9-1)
sid: resolved (fixed in 1.7.9-1)
trixie: resolved (fixed in 1.7.9-1)
OSV
angular Prototype Pollution vulnerability
osv·2019-11-20
CVE-2019-10768 [HIGH] angular Prototype Pollution vulnerability
angular Prototype Pollution vulnerability
Versions of `angular ` prior to 1.7.9 are vulnerable to prototype pollution. The deprecated API function `merge()` does not restrict the modification of an Object's prototype in the , which may allow an attacker to add or modify an existing property that will exist on all objects.
## Recommendation
Upgrade to version 1.7.9 or later. The function was already deprecated and upgrades are not expected to break functionality.
GHSA
angular Prototype Pollution vulnerability
ghsa·2019-11-20
CVE-2019-10768 [HIGH] CWE-1321 angular Prototype Pollution vulnerability
angular Prototype Pollution vulnerability
Versions of `angular ` prior to 1.7.9 are vulnerable to prototype pollution. The deprecated API function `merge()` does not restrict the modification of an Object's prototype in the , which may allow an attacker to add or modify an existing property that will exist on all objects.
## Recommendation
Upgrade to version 1.7.9 or later. The function was already deprecated and upgrades are not expected to break functionality.
OSV
CVE-2019-10768: In AngularJS before 1
osv·2019-11-19·CVSS 7.5
CVE-2019-10768 [HIGH] CVE-2019-10768: In AngularJS before 1
In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.
No detection rules found.
No public exploits indexed.
https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3Ehttps://snyk.io/vuln/SNYK-JS-ANGULAR-534884https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3Ehttps://snyk.io/vuln/SNYK-JS-ANGULAR-534884
2019-11-19
Published