yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload.
CVE: (none) => CVE-2020-7608
fix pushed in cauldron.
Resolution: (none) => FIXEDCC: (none) => mageiaStatus: NEW => RESOLVED
nodejs-yargs-parser-10.0.0-5.mga8 was the fixed version. Mageia 7 is also affected.
Source RPM: nodejs-yargs-parser-10.0.0-4.mga8.src.rpm => nodejs-yargs-parser-10.0.0-3.mga7.src.rpmVersion: Cauldron => 7Resolution: FIXED => (none)Status: RESOLVED => REOPENEDSummary: nodejs-yargs-parser security issue CVE-2020-7608 => nodejs-yargs-parser new security issue CVE-2020-7608
This is for you Stig.
CC: (none) => ouaurelienAssignee: bugsquad => smelror
fix pushed in mga7: src: - nodejs-yargs-parser-10.0.0-3.1.mga7
Assignee: smelror => qa-bugs
MGA7-64 MATE on Peaq C1011 No installation issues. No previous updates. This is developers territory, so OK on clean install.
CC: (none) => herman.viaeneWhiteboard: (none) => MGA7-64-OK
Validating.
Keywords: (none) => validated_updateCC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => advisory
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2021-0170.html
Resolution: (none) => FIXEDStatus: REOPENED => RESOLVED