Bug 27975

Summary: nodejs-yargs-parser new security issue CVE-2020-7608
Product: Mageia Reporter: Zombie Ryushu <zombie_ryushu>
Component: SecurityAssignee: QA Team <qa-bugs>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: andrewsfarm, herman.viaene, mageia, ouaurelien, sysadmin-bugs
Version: 7Keywords: advisory, validated_update
Target Milestone: ---   
Hardware: All   
OS: Linux   
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-7608
Whiteboard: MGA7-64-OK
Source RPM: nodejs-yargs-parser-10.0.0-3.mga7.src.rpm CVE: CVE-2020-7608
Status comment:

Description Zombie Ryushu 2020-12-29 11:15:29 CET
yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload.
Zombie Ryushu 2020-12-29 11:15:48 CET

CVE: (none) => CVE-2020-7608

Comment 1 Nicolas Lécureuil 2020-12-29 13:02:31 CET
fix pushed in cauldron.

Resolution: (none) => FIXED
CC: (none) => mageia
Status: NEW => RESOLVED

Comment 2 David Walser 2020-12-29 16:46:31 CET
nodejs-yargs-parser-10.0.0-5.mga8 was the fixed version.

Mageia 7 is also affected.

Source RPM: nodejs-yargs-parser-10.0.0-4.mga8.src.rpm => nodejs-yargs-parser-10.0.0-3.mga7.src.rpm
Version: Cauldron => 7
Resolution: FIXED => (none)
Status: RESOLVED => REOPENED
Summary: nodejs-yargs-parser security issue CVE-2020-7608 => nodejs-yargs-parser new security issue CVE-2020-7608

Comment 3 Aurelien Oudelet 2020-12-29 21:14:59 CET
This is for you Stig.

CC: (none) => ouaurelien
Assignee: bugsquad => smelror

Comment 4 Nicolas Lécureuil 2021-03-10 08:39:03 CET
fix pushed in mga7:

src:
    - nodejs-yargs-parser-10.0.0-3.1.mga7

Assignee: smelror => qa-bugs

Comment 5 Herman Viaene 2021-04-02 14:05:15 CEST
MGA7-64 MATE on Peaq C1011
No installation issues. 
No previous updates. This is developers territory, so OK on clean install.

CC: (none) => herman.viaene
Whiteboard: (none) => MGA7-64-OK

Comment 6 Thomas Andrews 2021-04-02 16:58:17 CEST
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Thomas Backlund 2021-04-02 21:17:22 CEST

Keywords: (none) => advisory

Comment 7 Mageia Robot 2021-04-02 22:26:37 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0170.html

Resolution: (none) => FIXED
Status: REOPENED => RESOLVED