CVE-2020-1321
published 2020-06-09CVE-2020-1321: A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory, aka 'Microsoft Office Remote Code…
PriorityP354high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
11.63%
95.6th percentile
A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory, aka 'Microsoft Office Remote Code Execution Vulnerability'.
Affected
70 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ajv.js | ajv | >= 0 < 6.12.3 | 6.12.3 |
| aws-sdk | shared-ini-file-loader | >= 0 < 1.0.0-rc.9 | 1.0.0-rc.9 |
| bmoor_project | bmoor | >= 0 < 0.10.1 | 0.10.1 |
| chaijis | pathval | >= 0 < 1.1.1 | 1.1.1 |
| class-transformer_project | class-transformer | >= 0 < 0.3.1 | 0.3.1 |
| confinit_project | confinit | >= 0 < 0.4.0 | 0.4.0 |
| connie-lang_project | connie-lang | >= 0 < 0.1.1 | 0.1.1 |
| deep-set_project | deep-set | 1.0.0 – 1.0.1 | — |
| dot-prop_project | dot-prop | >= 0 < 4.2.1 | 4.2.1 |
| dot-prop_project | dot-prop | >= 5.0.0 < 5.1.1 | 5.1.1 |
| eivifj | dot | >= 0 < 1.0.3 | 1.0.3 |
| exodus | field | 0.0.1 – 1.0.1 | — |
| fun-map_project | fun-map | 0 – 3.3.1 | — |
| grpc | grpc | >= 0 < 1.24.4 | 1.24.4 |
| grpc | grpc-js | >= 0 < 1.1.8 | 1.1.8 |
| hapi | hoek | >= 0 < 8.5.1 | 8.5.1 |
| hapi | hoek | >= 9.0.0 < 9.0.3 | 9.0.3 |
| hapijs | hoek | 0 – 6.1.3 | — |
| immer_project | immer | >= 7.0.0 < 9.0.6 | 9.0.6 |
| js-data | js-data | 0 – 3.0.10 | — |
| js-ini_project | js-ini | >= 0 < 1.3.0 | 1.3.0 |
| json-pointer_project | json-pointer | >= 0 < 0.6.2 | 0.6.2 |
| libnested_project | libnested | >= 0 < 1.5.2 | 1.5.2 |
| linuxfoundation | dojo | >= 0 < 1.11.10 | 1.11.10 |
| linuxfoundation | dojo | >= 1.12.0 < 1.12.8 | 1.12.8 |
Detection & IOCsextracted from sources · hover to see the quote
- →Attack vector requires a user to open a specially crafted file with an affected version of Microsoft Office software; the Preview Pane is NOT an attack vector ↗
- →Web-based delivery vector: attacker hosts or leverages a compromised website serving a specially crafted Office file to exploit the vulnerability ↗
- →Preview Pane is confirmed NOT an attack vector — detections should focus on full file-open events in Office processes, not preview rendering ↗
- ·Patches for Microsoft Office 2016 for Mac and Microsoft Office 2019 for Mac were not immediately available at time of advisory publication; detection coverage on Mac endpoints may be incomplete until patched ↗
- ·Exploit status at time of advisory: not publicly disclosed and not exploited in the wild; exploitation assessed as 'Less Likely' for both latest and older software releases ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa9.8CRITICAL
vendor_msrc8.8HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
hapi/hoek: Prototype Pollution in @hapi/hoek
vendor_redhat·2022-09-23·CVSS 8.1
CVE-2020-36604 [HIGH] CWE-1321 hapi/hoek: Prototype Pollution in @hapi/hoek
hapi/hoek: Prototype Pollution in @hapi/hoek
hoek before 8.5.1 and 9.x before 9.0.3 allows prototype poisoning in the clone function.
A prototype pollution flaw was found the clone() function of the hapi/hoek package. By adding or modifying properties of Object.prototype using a __proto__ or constructor payload, an attacker could execute arbitrary code or cause a denial of service condition on the system.
Package: rhmtc/openshift-migration-ui-rhel8 (Migration Toolkit for Containers) - Will not fix
Package: migration-toolkit-virtualization/mtv-ui-rhel8 (Migration Toolkit for Virtualization) - Fix deferred
Package: odo (OpenShift Developer Tools and Services) - Will not fix
Package: openshift-service-mesh/kiali-rhel8 (OpenShift Service Mesh 2) - Will not fix
Package: openshift-service
Microsoft
All versions of package datatables.net are vulnerable to Prototype Pollution
vendor_msrc·2020-12-08·CVSS 7.3
CVE-2020-28458 [HIGH] CWE-1321 All versions of package datatables.net are vulnerable to Prototype Pollution
All versions of package datatables.net are vulnerable to Prototype Pollution
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Snyk: Snyk
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Refer
Microsoft
Microsoft Office Remote Code Execution Vulnerability
vendor_msrc·2020-06-09·CVSS 8.8
CVE-2020-1321 [HIGH] Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the same permissions as the current user.
To exploit the vulnerability, a user must open a specially crafted file with an affected version of Microsoft Office software. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario, an
GHSA
FurqanSoftware/node-whois vulnerable to Prototype Pollution
ghsa·2022-12-19
CVE-2020-36618 [CRITICAL] CWE-1321 FurqanSoftware/node-whois vulnerable to Prototype Pollution
FurqanSoftware/node-whois vulnerable to Prototype Pollution
A vulnerability classified as critical has been found in Furqan node-whois. Affected is an unknown function of the file `index.coffee`. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). It is possible to launch the attack remotely. The name of the patch is 46ccc2aee8d063c7b6b4dee2c2834113b7286076. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216252.
GHSA
hoek subject to prototype pollution via the clone function.
ghsa·2022-09-25
CVE-2020-36604 [HIGH] CWE-1321 hoek subject to prototype pollution via the clone function.
hoek subject to prototype pollution via the clone function.
hoek versions prior to 8.5.1, and 9.x prior to 9.0.3 are vulnerable to prototype pollution in the clone function. If an object with the __proto__ key is passed to clone() the key is converted to a prototype. This issue has been patched in version 9.0.3, and backported to 8.5.1.
GHSA
js-ini Prorotype Pollution when malicious INI files submitted to an application that parses it with `parse`
ghsa·2022-07-26
CVE-2020-28461 [CRITICAL] CWE-1321 js-ini Prorotype Pollution when malicious INI files submitted to an application that parses it with `parse`
js-ini Prorotype Pollution when malicious INI files submitted to an application that parses it with `parse`
This affects the package js-ini before 1.3.0. If an attacker submits a malicious INI file to an application that parses it with `parse` , they will pollute the prototype on the application. This can be exploited further depending on the context.
GHSA
ion-parser Prototype Pollution when malicious INI file submitted to application that parses with `parse`
ghsa·2022-07-26
CVE-2020-28462 [CRITICAL] CWE-1321 ion-parser Prototype Pollution when malicious INI file submitted to application that parses with `parse`
ion-parser Prototype Pollution when malicious INI file submitted to application that parses with `parse`
This affects all versions of package ion-parser. If an attacker submits a malicious INI file to an application that parses it with `parse` , they will pollute the prototype on the application. This can be exploited further depending on the context.
GHSA
Prototype Pollution in deep-get-set
ghsa·2022-06-25·CVSS 9.8
CVE-2022-21231 [CRITICAL] CWE-1321 Prototype Pollution in deep-get-set
Prototype Pollution in deep-get-set
All versions of package deep-get-set are vulnerable to Prototype Pollution via the 'deep' function. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7715](https://security.snyk.io/vuln/SNYK-JS-DEEPGETSET-598666)
GHSA
Prototype Pollution in querymen
ghsa·2022-06-18·CVSS 5.3
CVE-2022-25871 [MEDIUM] CWE-1321 Prototype Pollution in querymen
Prototype Pollution in querymen
All versions of package querymen are vulnerable to Prototype Pollution if the parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. Note: This vulnerability derives from an incomplete fix of [CVE-2020-7600](https://security.snyk.io/vuln/SNYK-JS-QUERYMEN-559867).
GHSA
Prototype Pollution in mout
ghsa·2022-06-18·CVSS 7.5
CVE-2022-21213 [HIGH] CWE-1321 Prototype Pollution in mout
Prototype Pollution in mout
This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn mixes objects into the target object, recursively mixing existing child objects as well. In both cases, the key used to access the target object recursively is not checked, leading to exploiting this vulnerability. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7792](https://security.snyk.io/vuln/SNYK-JS-MOUT-1014544).
GHSA
GHSA-gc2g-h2mr-f7cg: A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory, aka 'Microsoft Office Re
ghsa_unreviewed·2022-05-24
CVE-2020-1321 [MEDIUM] CWE-119 GHSA-gc2g-h2mr-f7cg: A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory, aka 'Microsoft Office Re
A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory, aka 'Microsoft Office Remote Code Execution Vulnerability'.
GHSA
Prototype pollution in @strikeentco/set
ghsa·2022-05-24
CVE-2020-28267 [HIGH] CWE-1321 Prototype pollution in @strikeentco/set
Prototype pollution in @strikeentco/set
Prototype pollution vulnerability in '@strikeentco/set' version 1.0.0 allows attacker to cause a denial of service and may lead to remote code execution.
GHSA
Prototype pollution vulnerability in 'deep-set'
ghsa·2022-05-24
CVE-2020-28276 [CRITICAL] CWE-1321 Prototype pollution vulnerability in 'deep-set'
Prototype pollution vulnerability in 'deep-set'
The NPM module 'deep-set' can be abused by Prototype Pollution vulnerability since the function `deepSet()` does not check for the type of object before assigning value to the property. Due to this flaw an attacker could create a non-existent property or able to manipulate the property which leads to Denial of Service or potentially Remote code execution.
### PoC
```js
var deepSet = require('deep-set')
var obj = {'1':'2'}
console.log(obj.isAdmin);
deepSet(obj, '__proto__.isAdmin', 'true')
console.log(obj.isAdmin);
```
GHSA
Prototype Pollution in madlib-object-utils
ghsa·2022-04-16·CVSS 9.8
CVE-2022-24279 [CRITICAL] CWE-1321 Prototype Pollution in madlib-object-utils
Prototype Pollution in madlib-object-utils
The package madlib-object-utils before version 0.1.8 is vulnerable to Prototype Pollution via the `setValue` method, as it allows an attacker to merge object prototypes into it. *Note:* This vulnerability derives from an incomplete fix of [CVE-2020-7701](https://security.snyk.io/vuln/SNYK-JS-MADLIBOBJECTUTILS-598676)
GHSA
Prototype Pollution in libnested
ghsa·2022-03-18·CVSS 9.8
CVE-2022-25352 [CRITICAL] CWE-1321 Prototype Pollution in libnested
Prototype Pollution in libnested
The package libnested before 1.5.2 are vulnerable to Prototype Pollution via the set function in index.js. **Note:** This vulnerability derives from an incomplete fix for [CVE-2020-28283](https://security.snyk.io/vuln/SNYK-JS-LIBNESTED-1054930)
GHSA
Prototype Pollution in set-in
ghsa·2022-03-18·CVSS 9.8
CVE-2022-25354 [CRITICAL] CWE-1321 Prototype Pollution in set-in
Prototype Pollution in set-in
The package set-in before 2.0.3 is vulnerable to Prototype Pollution via the `setIn` method, as it allows an attacker to merge object prototypes into it. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-28273](https://security.snyk.io/vuln/SNYK-JS-SETIN-1048049)
GHSA
Prototype pollution in pathval
ghsa·2022-02-10
CVE-2020-7751 [HIGH] CWE-1321 Prototype pollution in pathval
Prototype pollution in pathval
A prototype pollution vulnerability affects all versions of package pathval under 1.1.1.
GHSA
Prototype Pollution in safetydance
ghsa·2022-02-10
CVE-2020-7737 [HIGH] CWE-1321 Prototype Pollution in safetydance
Prototype Pollution in safetydance
All versions of package safetydance are vulnerable to Prototype Pollution via the set function.
GHSA
Prototype Pollution in Ajv
ghsa·2022-02-10
CVE-2020-15366 [MEDIUM] CWE-1321 Prototype Pollution in Ajv
Prototype Pollution in Ajv
An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an untrusted schema should be a denial of service, not execution of code.)
GHSA
Prototype Pollution in bmoor
ghsa·2022-02-01·CVSS 9.8
CVE-2021-23558 [HIGH] CWE-1321 Prototype Pollution in bmoor
Prototype Pollution in bmoor
The package bmoor before 0.10.1 is vulnerable to Prototype Pollution due to missing sanitization in set function. **Note:** This vulnerability derives from an incomplete fix in [CVE-2020-7736](https://security.snyk.io/vuln/SNYK-JS-BMOOR-598664)
GHSA
Prototype Pollution in js-data
ghsa·2022-01-06·CVSS 9.8
CVE-2021-23574 [HIGH] CWE-1321 Prototype Pollution in js-data
Prototype Pollution in js-data
All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn and the set functions. This is an incomplete fix of [CVE-2020-28442](https://snyk.io/vuln/SNYK-JS-JSDATA-1023655).
GHSA
Uncontrolled Resource Consumption in fun-map
ghsa·2021-12-10
CVE-2020-7644 [HIGH] CWE-1321 Uncontrolled Resource Consumption in fun-map
Uncontrolled Resource Consumption in fun-map
fun-map through 3.3.1 is vulnerable to Prototype Pollution. The function assocInM could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
GHSA
Prototype Pollution in field
ghsa·2021-12-10
CVE-2020-28269 [CRITICAL] CWE-1321 Prototype Pollution in field
Prototype Pollution in field
Prototype pollution vulnerability in 'field' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
GHSA
Prototype Pollution via file load in aws-sdk and @aws-sdk/shared-ini-file-loader
ghsa·2021-11-16
CVE-2020-28472 [HIGH] CWE-1321 Prototype Pollution via file load in aws-sdk and @aws-sdk/shared-ini-file-loader
Prototype Pollution via file load in aws-sdk and @aws-sdk/shared-ini-file-loader
This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an attacker submits a malicious INI file to an application that parses it with loadSharedConfigFiles , they will pollute the prototype on the application. This can be exploited further depending on the context.
GHSA
Prototype Pollution in json-pointer
ghsa·2021-11-08·CVSS 7.2
CVE-2021-23820 [MEDIUM] CWE-1321 Prototype Pollution in json-pointer
Prototype Pollution in json-pointer
This affects versions of package `json-pointer` up to and including `0.6.1`. A type confusion vulnerability can lead to a bypass of CVE-2020-7709 when the pointer components are arrays.
GHSA
Prototype pollution in object-hierarchy-access
ghsa·2021-10-12
CVE-2020-28270 [CRITICAL] CWE-1321 Prototype pollution in object-hierarchy-access
Prototype pollution in object-hierarchy-access
Overview:Prototype pollution vulnerability in ‘object-hierarchy-access’ versions 0.2.0 through 0.32.0 allows attacker to cause a denial of service and may lead to remote code execution.
GHSA
Prototype Pollution in immer
ghsa·2021-09-02·CVSS 7.5
CVE-2021-23436 [HIGH] CWE-1321 Prototype Pollution in immer
Prototype Pollution in immer
This affects the package immer before 9.0.6. A type confusion vulnerability can lead to a bypass of CVE-2020-28477 when the user-provided keys used in the path parameter are arrays. In particular, this bypass is possible because the condition `(p === "__proto__" || p === "constructor")` in `applyPatches_` returns false if `p` is `['__proto__']` (or `['constructor']`). The `===` operator (strict equality operator) returns false if the operands have different type.
GHSA
eivindfjeldstad-dot contains prototype pollution vulnerability
ghsa·2021-05-25
CVE-2020-7639 [MEDIUM] CWE-1321 eivindfjeldstad-dot contains prototype pollution vulnerability
eivindfjeldstad-dot contains prototype pollution vulnerability
eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
GHSA
Prototype pollution in grpc and @grpc/grpc-js
ghsa·2021-05-10
CVE-2020-7768 [HIGH] CWE-1321 Prototype pollution in grpc and @grpc/grpc-js
Prototype pollution in grpc and @grpc/grpc-js
"The package grpc before 1.24.4 and the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition."
GHSA
Prototype Pollution in tiny-conf
ghsa·2021-05-10
CVE-2020-7724 [CRITICAL] CWE-1321 Prototype Pollution in tiny-conf
Prototype Pollution in tiny-conf
All versions of package tiny-conf up to and including version 1.1.0 are vulnerable to Prototype Pollution via the set function.
GHSA
TypeORM vulnerable to MAID and Prototype Pollution
ghsa·2021-05-07
CVE-2020-8158 [CRITICAL] CWE-1321 TypeORM vulnerable to MAID and Prototype Pollution
TypeORM vulnerable to MAID and Prototype Pollution
Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks.
GHSA
Prototype Pollution in nis-utils
ghsa·2021-05-06
CVE-2020-7703 [CRITICAL] CWE-1321 Prototype Pollution in nis-utils
Prototype Pollution in nis-utils
All versions of package nis-utils up to and including 0.6.10 are vulnerable to Prototype Pollution via the setValue function.
GHSA
Prototype Pollution in property-expr
ghsa·2021-05-06
CVE-2020-7707 [CRITICAL] CWE-1321 Prototype Pollution in property-expr
Prototype Pollution in property-expr
The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.
GHSA
Prototype Pollution in arr-flatten-unflatten
ghsa·2021-05-06
CVE-2020-7713 [CRITICAL] CWE-1321 Prototype Pollution in arr-flatten-unflatten
Prototype Pollution in arr-flatten-unflatten
All versions of package arr-flatten-unflatten up to and including version 1.1.4 are vulnerable to Prototype Pollution via the constructor.
GHSA
Prototype Pollution in templ8
ghsa·2021-05-06
CVE-2020-7702 [CRITICAL] CWE-1321 Prototype Pollution in templ8
Prototype Pollution in templ8
All versions of package templ8 up to and including 0.0.44 are vulnerable to Prototype Pollution via the parse function.
GHSA
Prototype Pollution in gedi
ghsa·2021-05-06
CVE-2020-7727 [CRITICAL] CWE-1321 Prototype Pollution in gedi
Prototype Pollution in gedi
All versions of package gedi up to and including version 1.6.3 are vulnerable to Prototype Pollution via the set function.
GHSA
Prototype Pollution in promisehelpers
ghsa·2021-05-06
CVE-2020-7723 [CRITICAL] CWE-1321 Prototype Pollution in promisehelpers
Prototype Pollution in promisehelpers
All versions of package promisehelpers up to and including version 0.0.5 are vulnerable to Prototype Pollution via the insert function.
GHSA
Prototype Pollution in connie-lang
ghsa·2021-05-06
CVE-2020-7706 [CRITICAL] CWE-1321 Prototype Pollution in connie-lang
Prototype Pollution in connie-lang
The package connie-lang before 0.1.1 are vulnerable to Prototype Pollution in the configuration language library used by connie.
GHSA
Prototype Pollution in confucious
ghsa·2021-05-06
CVE-2020-7714 [CRITICAL] CWE-1321 Prototype Pollution in confucious
Prototype Pollution in confucious
All versions of package confucious up to and including version 0.0.12 are vulnerable to Prototype Pollution via the set function.
GHSA
Prototype Pollution in safe-object2
ghsa·2021-05-06
CVE-2020-7726 [CRITICAL] CWE-1321 Prototype Pollution in safe-object2
Prototype Pollution in safe-object2
All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function.
GHSA
Prototype pollution in set-object-value
ghsa·2021-04-13
CVE-2020-28281 [CRITICAL] CWE-1321 Prototype pollution in set-object-value
Prototype pollution in set-object-value
Prototype pollution vulnerability in 'set-object-value' versions 0.0.0 through 0.0.5 allows an attacker to cause a denial of service and may lead to remote code execution.
GHSA
Prototype Pollution in y18n
ghsa·2021-03-29
CVE-2020-7774 [HIGH] CWE-1321 Prototype Pollution in y18n
Prototype Pollution in y18n
### Overview
The npm package `y18n` before versions 3.2.2, 4.0.1, and 5.0.5 is vulnerable to Prototype Pollution.
### POC
```js
const y18n = require('y18n')();
y18n.setLocale('__proto__');
y18n.updateLocale({polluted: true});
console.log(polluted); // true
```
### Recommendation
Upgrade to version 3.2.2, 4.0.1, 5.0.5 or later.
GHSA
Prototype pollution in total.js
ghsa·2021-02-05
CVE-2020-28495 [HIGH] CWE-1321 Prototype pollution in total.js
Prototype pollution in total.js
There is a prototype pollution vulnerability in the package total.js before version 3.4.7. The set function can be used to set a value into the object according to the path. However the keys of the path being set are not properly sanitized, leading to a prototype pollution vulnerability. The impact depends on the application. In some cases it is possible to achieve Denial of service (DoS), Remote Code Execution or Property Injection.
GHSA
yargs-parser Vulnerable to Prototype Pollution
ghsa·2020-09-04
CVE-2020-7608 [MEDIUM] CWE-1321 yargs-parser Vulnerable to Prototype Pollution
yargs-parser Vulnerable to Prototype Pollution
Affected versions of `yargs-parser` are vulnerable to prototype pollution. Arguments are not properly sanitized, allowing an attacker to modify the prototype of `Object`, causing the addition or modification of an existing property that will exist on all objects.
Parsing the argument `--foo.__proto__.bar baz'` adds a `bar` property with value `baz` to all objects. This is only exploitable if attackers have control over the arguments being passed to `yargs-parser`.
## Recommendation
Upgrade to versions 13.1.2, 15.0.1, 18.1.1 or later.
GHSA
dot-prop Prototype Pollution vulnerability
ghsa·2020-07-29
CVE-2020-8116 [HIGH] CWE-1321 dot-prop Prototype Pollution vulnerability
dot-prop Prototype Pollution vulnerability
Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language constructs such as objects.
GHSA
Prototype Pollution in lodash
ghsa·2020-07-15
CVE-2020-8203 [HIGH] CWE-1321 Prototype Pollution in lodash
Prototype Pollution in lodash
Versions of lodash prior to 4.17.19 are vulnerable to Prototype Pollution. The functions `pick`, `set`, `setWith`, `update`, `updateWith`, and `zipObjectDeep` allow a malicious user to modify the prototype of Object if the property identifiers are user-supplied. Being affected by this issue requires manipulating objects based on user-provided property values or arrays.
This vulnerability causes the addition or modification of an existing property that will exist on all objects and may lead to Denial of Service or Code Execution under specific circumstances.
GHSA
Class destructors causing side-effects when being unserialized in TYPO3 CMS
ghsa·2020-05-13
CVE-2020-11066 [HIGH] CWE-1321 Class destructors causing side-effects when being unserialized in TYPO3 CMS
Class destructors causing side-effects when being unserialized in TYPO3 CMS
Calling unserialize() on malicious user-submitted content can result in the following scenarios:
- trigger deletion of arbitrary directory in file system (if writable for web server)
- trigger message submission via email using identity of web site (mail relay)
Another insecure deserialization vulnerability is required to actually exploit mentioned aspects.
Update to TYPO3 versions 9.5.17 or 10.4.2 that fix the problem described.
### References
* https://typo3.org/security/advisory/typo3-core-sa-2020-004
GHSA
confinit vulnerable to prototype pollution
ghsa·2020-04-07
CVE-2020-7638 [MEDIUM] CWE-1321 confinit vulnerable to prototype pollution
confinit vulnerable to prototype pollution
confinit through 0.3.0 is vulnerable to Prototype Pollution.The 'setDeepProperty' function could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
GHSA
Prototype pollution in class-transformer
ghsa·2020-04-07
CVE-2020-7637 [MEDIUM] CWE-1321 Prototype pollution in class-transformer
Prototype pollution in class-transformer
class-transformer through 0.2.3 is vulnerable to Prototype Pollution. The 'classToPlainFromExist' function could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
GHSA
Prototype Pollution in minimist
ghsa·2020-04-03
CVE-2020-7598 [MEDIUM] CWE-1321 Prototype Pollution in minimist
Prototype Pollution in minimist
Affected versions of `minimist` are vulnerable to prototype pollution. Arguments are not properly sanitized, allowing an attacker to modify the prototype of `Object`, causing the addition or modification of an existing property that will exist on all objects.
Parsing the argument `--__proto__.y=Polluted` adds a `y` property with value `Polluted` to all objects. The argument `--__proto__=Polluted` raises and uncaught error and crashes the application.
This is exploitable if attackers have control over the arguments being passed to `minimist`.
## Recommendation
Upgrade to versions 0.2.1, 1.2.3 or later.
GHSA
Prototype pollution in dojo
ghsa·2020-03-10
CVE-2020-5258 [HIGH] CWE-1321 Prototype pollution in dojo
Prototype pollution in dojo
In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution.
Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects.
An attacker manipulates these attributes to overwrite, or pollute, a JavaScript application object prototype of the base object by injecting other values.
This has been patched in versions 1.12.8, 1.13.7, 1.14.6, 1.15.3 and 1.16.2
No detection rules found.
No public exploits indexed.
2020-06-09
Published