Vulnerability Name: | CVE-2019-10746 (CCN-167420) | ||||||||||||||||||
Assigned: | 2019-06-19 | ||||||||||||||||||
Published: | 2019-06-19 | ||||||||||||||||||
Updated: | 2022-10-29 | ||||||||||||||||||
Summary: | mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload. | ||||||||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C)
6.1 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||
Vulnerability Type: | CWE-88 CWE-471 | ||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-10746 Source: XF Type: UNKNOWN nodejs-cve201910746-dos(167420) Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2020-4a8f110332 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2020-f80e5c0d65 Source: CCN Type: SNYK-JS-MIXINDEEP-450212 Prototype Pollution Source: MISC Type: Exploit, Third Party Advisory https://snyk.io/vuln/SNYK-JS-MIXINDEEP-450212 Source: CCN Type: IBM Security Bulletin 6323247 (ICP Discovery) IBM Watson Discovery for IBM Cloud Pak for Data affected by vulnerability in Node.js modules Source: CCN Type: IBM Security Bulletin 6453115 (Cloud Pak for Security) Cloud Pak for Security contains security vulnerabilities Source: CCN Type: IBM Security Bulletin 6568787 (Cloud Pak for Security) Cloud Pak for Security contains packages that have multiple vulnerabilities Source: CCN Type: IBM Security Bulletin 6575649 (Spectrum Discover) Medium/low severity vulnerabilities in libraries used by IBM Spectrum Discover (libraries of libraries) Source: CCN Type: IBM Security Bulletin 6825871 (Tivoli Netcool/OMNIbus_GUI) Multiple vulnerabilities in React, webpack and Node.js modules affect Tivoli Netcool/OMNIbus WebGUI Source: CCN Type: IBM Security Bulletin 6956539 (MobileFirst Platform Foundation) Multiple vulnerabilities found with third-party libraries used by IBM MobileFirst Platform Source: CCN Type: NPM Web site mixin-deep Source: N/A Type: Patch, Third Party Advisory N/A Source: CCN Type: Oracle CPUJul2021 Oracle Critical Patch Update Advisory - July 2021 Source: CCN Type: WhiteSource Vulnerability Database CVE-2019-10746 | ||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration RedHat 1: Configuration RedHat 2: Configuration CCN 1: ![]() | ||||||||||||||||||
Oval Definitions | |||||||||||||||||||
| |||||||||||||||||||
BACK |