CVE-2020-7720
published 2020-09-01CVE-2020-7720: The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the…
PriorityP340high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
3.16%
86.6th percentile
The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-node-forge | < node-node-forge 0.10.0~dfsg-1 (bullseye) | node-node-forge 0.10.0~dfsg-1 (bullseye) |
| digitalbazaar | forge | < 0.10.0 | 0.10.0 |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
ghsa7.3HIGH
osv7.3HIGH
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
nodejs-node-forge: prototype pollution via the util.setPath function
vendor_redhat·2020-09-01·CVSS 9.8
CVE-2020-7720 [CRITICAL] CWE-400 nodejs-node-forge: prototype pollution via the util.setPath function
nodejs-node-forge: prototype pollution via the util.setPath function
The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.
A flaw was found in nodejs-node-forge. A Prototype Pollution via the util.setPath function is possible.
Statement: In Red Hat Openshift Container Storage 4 the noobaa-core container includes the affected version of node-forge as a dependency of google-p12-pem, however the vulnerable function `util.setPath` is not being used and hence this issue has been rated as having a security impact of Low.
In OpenShift Container Platform (OCP) the prometheus container is behind OpenShift OAuth restricting access to the vulnerable node-forge library to
Debian
CVE-2020-7720: node-node-forge - The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via th...
vendor_debian·2020·CVSS 9.8
CVE-2020-7720 [CRITICAL] CVE-2020-7720: node-node-forge - The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via th...
The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.
Scope: local
bullseye: resolved (fixed in 0.10.0~dfsg-1)
OSV
Prototype Pollution in node-forge util.setPath API
osv·2022-01-08·CVSS 7.3
[HIGH] Prototype Pollution in node-forge util.setPath API
Prototype Pollution in node-forge util.setPath API
### Impact
`forge.util.setPath` had a potential prototype pollution issue if called with untrusted keys. This API was not used by forge itself.
### Patches
The `forge.util.setPath` API and related functions were removed in 0.10.0.
### Workarounds
Don't call `forge.util.setPath` directly or indirectly with untrusted keys.
### References
- https://security.snyk.io/vuln/SNYK-JS-NODEFORGE-598677
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7720
### For more information
If you have any questions or comments about this advisory:
* Open an issue in [forge](https://github.com/digitalbazaar/forge).
* Email us at [email protected].
GHSA
Prototype Pollution in node-forge util.setPath API
ghsa·2022-01-08·CVSS 7.3
[HIGH] Prototype Pollution in node-forge util.setPath API
Prototype Pollution in node-forge util.setPath API
### Impact
`forge.util.setPath` had a potential prototype pollution issue if called with untrusted keys. This API was not used by forge itself.
### Patches
The `forge.util.setPath` API and related functions were removed in 0.10.0.
### Workarounds
Don't call `forge.util.setPath` directly or indirectly with untrusted keys.
### References
- https://security.snyk.io/vuln/SNYK-JS-NODEFORGE-598677
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7720
### For more information
If you have any questions or comments about this advisory:
* Open an issue in [forge](https://github.com/digitalbazaar/forge).
* Email us at [email protected].
GHSA
Prototype Pollution in node-forge
ghsa·2020-09-14
CVE-2020-7720 [HIGH] CWE-1321 Prototype Pollution in node-forge
Prototype Pollution in node-forge
The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: version 0.10.0 is a breaking change removing the vulnerable functions.
OSV
Prototype Pollution in node-forge
osv·2020-09-14
CVE-2020-7720 [HIGH] Prototype Pollution in node-forge
Prototype Pollution in node-forge
The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: version 0.10.0 is a breaking change removing the vulnerable functions.
OSV
CVE-2020-7720: The package node-forge before 0
osv·2020-09-01·CVSS 7.3
CVE-2020-7720 [HIGH] CVE-2020-7720: The package node-forge before 0
The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.
No detection rules found.
No public exploits indexed.
https://github.com/digitalbazaar/forge/blob/master/CHANGELOG.mdhttps://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-609293https://snyk.io/vuln/SNYK-JS-NODEFORGE-598677https://github.com/digitalbazaar/forge/blob/master/CHANGELOG.mdhttps://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-609293https://snyk.io/vuln/SNYK-JS-NODEFORGE-598677
2020-09-01
Published