Prototype pollution in minimist - CVE-2020-7598
Published: March 18, 2020 / Updated: July 22, 2020
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can inject and execute arbitrary script code.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
IBM Engineering Requirements Quality Assistant
IBM Watson Machine Learning Accelerator
IBM Planning Analytics Workspace
Cognos Dashboards on Cloud Pak for Data
QRadar Pulse App
Cloud Pak for Security (CP4S)
IBM QRadar Data Synchronization App
Red Hat OpenShift Container Platform
IBM Intelligent Operations Center
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Opensuse
openEuler
rh-nodejs10-nodejs (Red Hat package)
nodejs-minimist
rh-nodejs12-nodejs (Red Hat package)
IBM Security QRadar Analyst Workflow
IBM Cognos Analytics
How to mitigate CVE-2020-7598
QRadar Pulse App - update to 2.2.9
Cloud Pak for Security (CP4S) - update to 1.10.15.0
Red Hat OpenShift Container Platform - addressed in versions 4.5.8, 4.6.38
IBM Intelligent Operations Center - update to 5.2.4
rh-nodejs10-nodejs (Red Hat package) - update to 10.21.0-3.el7
nodejs-minimist - update to 1.2.0-2
IBM Planning Analytics Workspace - update to 2.0.93
IBM Security QRadar Analyst Workflow - update to 2.31.4
IBM QRadar Data Synchronization App - update to 3.1.0
Cognos Dashboards on Cloud Pak for Data - update to 5.1.1
IBM Cognos Analytics - addressed in versions 11.1.7.6, 11.2.4.1 IF1
rh-nodejs12-nodejs (Red Hat package) - update to 12.18.2-1.el7
External References
Related Security Bulletins
- Code Injection in minimist package for NPM
- Red Hat Software Collections update for rh-nodejs10-nodejs
- OpenSUSE Linux update for nodejs8
- Multiple vulnerabilities in OpenShift Container Platform 4.6
- Multiple vulnerabilities in IBM QRadar Pulse for QRadar SIEM
- Multiple vulnerabilities in IBM Engineering Requirements Quality Assistant On-Premises
- Red Hat Software Collections update for rh-nodejs12-nodejs
- Multiple vulnerabilities in IBM Cognos Analytics
- Multiple vulnerabilities in IBM Intelligent Operations Center
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in IBM QRadar Data Synchronization App
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data
- openEuler update for nodejs-minimist
- Multiple vulnerabilities in IBM Planning Analytics Workspace
- Multiple vulnerabilities in IBM Analyst Workflow
- Multiple vulnerabilities in IBM Cognos Dashboards on Cloud Pak for Data
- Red Hat Enterprise Linux 8 update for the nodejs:10 module
- Red Hat Enterprise Linux 8 update for the nodejs:10 module
- Red Hat Enterprise Linux 8 update for the nodejs:12 module
- Red Hat Enterprise Linux 8 update for the nodejs:12 module
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.5