Lucene search

K
cvelistSnykCVELIST:CVE-2020-7746
HistoryOct 29, 2020 - 12:00 a.m.

CVE-2020-7746 Prototype Pollution

2020-10-2900:00:00
snyk
www.cve.org
1

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:U/RC:C

9.4 High

AI Score

Confidence

High

0.016 Low

EPSS

Percentile

87.3%

This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing options (or the defaults options) are deeply merged with provided options. However, during this operation, the keys of the object being set are not checked, leading to a prototype pollution.

CNA Affected

[
  {
    "product": "chart.js",
    "vendor": "n/a",
    "versions": [
      {
        "lessThan": "2.9.4",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:U/RC:C

9.4 High

AI Score

Confidence

High

0.016 Low

EPSS

Percentile

87.3%