CVE-2020-28458Prototype Pollution in Datatables.net

Severity
7.3HIGHNVD
EPSS
1.2%
top 20.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 16
Latest updateDec 17

Description

All versions of package datatables.net are vulnerable to Prototype Pollution due to an incomplete fix for https://snyk.io/vuln/SNYK-JS-DATATABLESNET-598806.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 3.9 | Impact: 3.4

Affected Packages7 packages

Patches

🔴Vulnerability Details

2
GHSA
datatables.net vulnerable to Prototype Pollution due to incomplete fix2020-12-17
OSV
datatables.net vulnerable to Prototype Pollution due to incomplete fix2020-12-17

📋Vendor Advisories

2
Microsoft
All versions of package datatables.net are vulnerable to Prototype Pollution2020-12-08
Red Hat
datatables.net: prototype pollution if 'constructor' were used in a data property name2020-10-25
CVE-2020-28458 — Prototype Pollution in Datatables.net | cvebase