Severity
7.3HIGHNVD
EPSS
2.1%
top 15.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 1
Latest updateJan 8

Description

The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 3.9 | Impact: 3.4

Affected Packages2 packages

debiandebian/node-node-forge< node-node-forge 0.10.0~dfsg-1 (bullseye)
NVDdigitalbazaar/forge< 0.10.0

🔴Vulnerability Details

5
OSV
Prototype Pollution in node-forge util.setPath API2022-01-08
GHSA
Prototype Pollution in node-forge util.setPath API2022-01-08
GHSA
Prototype Pollution in node-forge2020-09-14
OSV
Prototype Pollution in node-forge2020-09-14
OSV
CVE-2020-7720: The package node-forge before 02020-09-01

📋Vendor Advisories

2
Red Hat
nodejs-node-forge: prototype pollution via the util.setPath function2020-09-01
Debian
CVE-2020-7720: node-node-forge - The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via th...2020

💬Community

1
Bugzilla
CVE-2020-7720 nodejs-node-forge: prototype pollution via the util.setPath function2020-09-01
CVE-2020-7720 — Prototype Pollution in Forge | cvebase