CVE-2020-7774

Description

The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.637

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-3450,CVE-2021-3449,CVE-2020-7774 are fixed in Node.js 12 (x64) (12.22.1)Windows
Vulnerabilities CVE-2021-3450,CVE-2021-3449,CVE-2020-7774 are fixed in Node.js 12 (12.22.1)Windows
Vulnerabilities CVE-2021-3450,CVE-2021-3449,CVE-2020-7774 are fixed in Node.js 12 (x64) (12.22.10)Windows
Vulnerabilities CVE-2021-3450,CVE-2021-3449,CVE-2020-7774 are fixed in Node.js 12 (12.22.10)Windows
Vulnerabilities CVE-2021-3450,CVE-2021-3449,CVE-2020-7774 are fixed in Node.js 12 (x64) (12.22.11)Windows
Vulnerabilities CVE-2021-3450,CVE-2021-3449,CVE-2020-7774 are fixed in Node.js 12 (12.22.11)Windows
Vulnerabilities CVE-2021-3450,CVE-2021-3449,CVE-2020-7774 are fixed in Node.js 12 (x64) (12.22.12)Windows
Vulnerabilities CVE-2021-3450,CVE-2021-3449,CVE-2020-7774 are fixed in Node.js 12 (12.22.12)Windows
Vulnerabilities CVE-2021-3450,CVE-2021-3449,CVE-2020-7774 are fixed in Node.js 14 (x64) (14.16.1)Windows
Vulnerabilities CVE-2021-3450,CVE-2021-3449,CVE-2020-7774 are fixed in Node.js 14 (14.16.1)Windows
Vulnerabilities CVE-2021-3450,CVE-2021-3449,CVE-2020-7774 are fixed in Node.js 10 (x64) (10.24.1)Windows
Vulnerabilities CVE-2021-3450,CVE-2021-3449,CVE-2020-7774 are fixed in Node.js 10 (10.24.1)Windows
Vulnerabilities CVE-2021-3450,CVE-2021-3449,CVE-2020-7774 are fixed in Node.js 15.14.0Windows
Multiple Vulnerabilities are affected in IBM WebMethods Integration Server 10.15Windows
Multiple Vulnerabilities are affected in IBM WebMethods Integration Server 10.11Windows
Multiple Vulnerabilities are affected in IBM WebMethods Integration Server 11.1Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 20.0Windows
(RHSA-2020:5499) nodejs:12 security and bug fix update nodejs-12.19.1-1.module+el8.3.0+8851+b7b41ca0.x86_64.rpmLinux
(RHSA-2020:5499) nodejs:12 security and bug fix update nodejs-debugsource-12.19.1-1.module+el8.3.0+8851+b7b41ca0.x86_64.rpmLinux
(RHSA-2020:5499) nodejs:12 security and bug fix update nodejs-devel-12.19.1-1.module+el8.3.0+8851+b7b41ca0.x86_64.rpmLinux
(RHSA-2020:5499) nodejs:12 security and bug fix update nodejs-docs-12.19.1-1.module+el8.3.0+8851+b7b41ca0.noarch.rpmLinux
(RHSA-2020:5499) nodejs:12 security and bug fix update nodejs-full-i18n-12.19.1-1.module+el8.3.0+8851+b7b41ca0.x86_64.rpmLinux
(RHSA-2020:5499) nodejs:12 security and bug fix update npm-6.14.8-1.12.19.1.1.module+el8.3.0+8851+b7b41ca0.x86_64.rpmLinux
(RHSA-2021:0551) nodejs:14 security and bug fix update nodejs-14.15.4-2.module+el8.3.0+9635+ffdf8381.x86_64.rpmLinux
(RHSA-2021:0551) nodejs:14 security and bug fix update nodejs-debugsource-14.15.4-2.module+el8.3.0+9635+ffdf8381.x86_64.rpmLinux
(RHSA-2021:0551) nodejs:14 security and bug fix update nodejs-devel-14.15.4-2.module+el8.3.0+9635+ffdf8381.x86_64.rpmLinux
(RHSA-2021:0551) nodejs:14 security and bug fix update nodejs-docs-14.15.4-2.module+el8.3.0+9635+ffdf8381.noarch.rpmLinux
(RHSA-2021:0551) nodejs:14 security and bug fix update nodejs-full-i18n-14.15.4-2.module+el8.3.0+9635+ffdf8381.x86_64.rpmLinux
(RHSA-2021:0551) nodejs:14 security and bug fix update nodejs-nodemon-2.0.3-1.module+el8.3.0+6519+9f98ed83.noarch.rpmLinux
(RHSA-2021:0551) nodejs:14 security and bug fix update nodejs-packaging-23-3.module+el8.3.0+6519+9f98ed83.noarch.rpmLinux
(RHSA-2021:0551) nodejs:14 security and bug fix update npm-6.14.10-1.14.15.4.2.module+el8.3.0+9635+ffdf8381.x86_64.rpmLinux
(RHSA-2021:0548)Moderate: security update nodejs-10.23.1-1.module+el8.3.0+9502+012d8a97.x86_64.rpmLinux
(RHSA-2021:0548)Moderate: security update nodejs-debuginfo-10.23.1-1.module+el8.3.0+9502+012d8a97.x86_64.rpmLinux
(RHSA-2021:0548)Moderate: security update nodejs-debugsource-10.23.1-1.module+el8.3.0+9502+012d8a97.x86_64.rpmLinux
(RHSA-2021:0548)Moderate: security update nodejs-devel-10.23.1-1.module+el8.3.0+9502+012d8a97.x86_64.rpmLinux
(RHSA-2021:0548)Moderate: security update nodejs-docs-10.23.1-1.module+el8.3.0+9502+012d8a97.noarch.rpmLinux
(RHSA-2021:0548)Moderate: security update nodejs-full-i18n-10.23.1-1.module+el8.3.0+9502+012d8a97.x86_64.rpmLinux
(RHSA-2021:0548)Moderate: security update nodejs-nodemon-1.18.3-1.module+el8+2632+6c5111ed.noarch.rpmLinux
(RHSA-2021:0548)Moderate: security update nodejs-packaging-17-3.module+el8+2873+aa7dfd9a.noarch.rpmLinux
(RHSA-2021:0548)Moderate: security update npm-6.14.10-1.10.23.1.1.module+el8.3.0+9502+012d8a97.x86_64.rpmLinux
Improperly Controlled Modification of Object Prototype Attributes (Prototype Pollution) Vulnerability (CVE-2020-7774)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-324371Node.js 12 (x64) (12.22.12)
PATCH-324370Node.js 12 (12.22.12)
PATCH-324371Node.js 12 (x64) (12.22.12)
PATCH-324370Node.js 12 (12.22.12)
PATCH-324371Node.js 12 (x64) (12.22.12)
PATCH-324370Node.js 12 (12.22.12)
PATCH-324371Node.js 12 (x64) (12.22.12)
PATCH-324370Node.js 12 (12.22.12)
PATCH-329083Node.js 14 (x64) (14.21.3)
PATCH-329082Node.js 14 (14.21.3)
PATCH-319043Node.js 10 (x64) (10.24.1)
PATCH-319042Node.js 10 (10.24.1)
PATCH-319042Node.js 10 (10.24.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234