-
-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
Auto Create IssuesLabel for Auto Created IssuesLabel for Auto Created IssuesCriticalThis label for Security Severity onlyThis label for Security Severity onlySecurityLabel for Security IssuesLabel for Security Issuesdo-not-autocloseMake bot can't close an Issues or PRsMake bot can't close an Issues or PRs
Milestone
Description
Description
Minimist prior to 1.2.6 and 0.2.4 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
Severity Check
- Low
- Moderate
- High
- Critical
Severity Number
9.8 / 10
CVSS base metrics
-
Attack vector
Network -
Attack complexity
Low -
Privileges required
None -
User interaction
None -
Scope
Unchanged -
Confidentiality
High -
Integrity
High -
Availability
High -
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
-
Weaknesses
CWE-1321 -
CVE ID
CVE-2021-44906 -
GHSA ID
GHSA-xvch-5gv4-984h
Information
Package minimist (npm)
Affected versions
= 1.0.0, < 1.2.6
< 0.2.4
Patched versions
1.2.6
0.2.4
References
- substack/minimist
- https://nvd.nist.gov/vuln/detail/CVE-2021-44906
- https://github.com/substack/minimist/issues/164
- https://github.com/substack/minimist/blob/master/index.js#L69
- https://snyk.io/vuln/SNYK-JS-MINIMIST-559764
- https://stackoverflow.com/questions/8588563/adding-custom-properties-to-a-function/20278068#20278068
- https://github.com/Marynk/JavaScript-vulnerability-detection/blob/main/minimist%20PoC.zip
- Backport of v1.2.6 fixes to v0.2.x? minimistjs/minimist#11
- Robustness: rework isConstructorOrProto minimistjs/minimist#24
- minimistjs/minimist@34e20b8
- minimistjs/minimist@bc8ecee
- minimistjs/minimist@c2b9819
- minimistjs/minimist@ef9153f
- https://github.com/minimistjs/minimist/commits/v0.2.4
Metadata
Metadata
Assignees
Labels
Auto Create IssuesLabel for Auto Created IssuesLabel for Auto Created IssuesCriticalThis label for Security Severity onlyThis label for Security Severity onlySecurityLabel for Security IssuesLabel for Security Issuesdo-not-autocloseMake bot can't close an Issues or PRsMake bot can't close an Issues or PRs