Bug 27975 - nodejs-yargs-parser new security issue CVE-2020-7608
Summary: nodejs-yargs-parser new security issue CVE-2020-7608
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: https://nvd.nist.gov/vuln/detail/CVE-...
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2020-12-29 11:15 CET by Zombie Ryushu
Modified: 2021-04-02 22:26 CEST (History)
5 users (show)

See Also:
Source RPM: nodejs-yargs-parser-10.0.0-3.mga7.src.rpm
CVE: CVE-2020-7608
Status comment:


Attachments

Description Zombie Ryushu 2020-12-29 11:15:29 CET
yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload.
Zombie Ryushu 2020-12-29 11:15:48 CET

CVE: (none) => CVE-2020-7608

Comment 1 Nicolas Lécureuil 2020-12-29 13:02:31 CET
fix pushed in cauldron.

Resolution: (none) => FIXED
CC: (none) => mageia
Status: NEW => RESOLVED

Comment 2 David Walser 2020-12-29 16:46:31 CET
nodejs-yargs-parser-10.0.0-5.mga8 was the fixed version.

Mageia 7 is also affected.

Source RPM: nodejs-yargs-parser-10.0.0-4.mga8.src.rpm => nodejs-yargs-parser-10.0.0-3.mga7.src.rpm
Version: Cauldron => 7
Resolution: FIXED => (none)
Status: RESOLVED => REOPENED
Summary: nodejs-yargs-parser security issue CVE-2020-7608 => nodejs-yargs-parser new security issue CVE-2020-7608

Comment 3 Aurelien Oudelet 2020-12-29 21:14:59 CET
This is for you Stig.

CC: (none) => ouaurelien
Assignee: bugsquad => smelror

Comment 4 Nicolas Lécureuil 2021-03-10 08:39:03 CET
fix pushed in mga7:

src:
    - nodejs-yargs-parser-10.0.0-3.1.mga7

Assignee: smelror => qa-bugs

Comment 5 Herman Viaene 2021-04-02 14:05:15 CEST
MGA7-64 MATE on Peaq C1011
No installation issues. 
No previous updates. This is developers territory, so OK on clean install.

CC: (none) => herman.viaene
Whiteboard: (none) => MGA7-64-OK

Comment 6 Thomas Andrews 2021-04-02 16:58:17 CEST
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Thomas Backlund 2021-04-02 21:17:22 CEST

Keywords: (none) => advisory

Comment 7 Mageia Robot 2021-04-02 22:26:37 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0170.html

Resolution: (none) => FIXED
Status: REOPENED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.