Prototype pollution in Ajv - CVE-2020-15366

 

Prototype pollution in Ajv - CVE-2020-15366

Published: August 2, 2021


Vulnerability identifier: #VU55498
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-15366
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can inject and execute arbitrary script code.


Affected software

Ajv
Watson AI Gateway for Cloud Pak for Data
IBM Watson Machine Learning Accelerator
Business Automation Insights
IBM Planning Analytics Workspace
MobileFirst Platform
Ansible Automation Platform
IBM Cloud Pak for Business Automation
QRadar User Behavior Analytics
Cloud Pak for Security (CP4S)
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
python-galaxy-importer (Red Hat package)
python-pulp-ansible (Red Hat package)
python-bleach-allowlist (Red Hat package)
python-bleach (Red Hat package)
automation-hub (Red Hat package)
python-galaxy-ng (Red Hat package)
rh-nodejs10-nodejs (Red Hat package)
rh-nodejs12-nodejs (Red Hat package)
rh-nodejs14-nodejs (Red Hat package)
IBM Cognos Analytics

How to mitigate CVE-2020-15366

Install update from vendor's website.

Ajv - update to 6.12.3
Watson AI Gateway for Cloud Pak for Data - update to 1.0.17
Cloud Pak for Security (CP4S) - update to 1.10.15.0
IBM Watson Machine Learning Accelerator - update to 2.3.4
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
python-galaxy-importer (Red Hat package) - addressed in versions 0.2.15-1.el7pc, 0.2.15-1.el8pc
python-pulp-ansible (Red Hat package) - addressed in versions 0.5.6-1.el7pc, 0.5.6-1.el8pc
python-bleach-allowlist (Red Hat package) - addressed in versions 1.0.3-1.el7pc, 1.0.3-1.el8pc
IBM Planning Analytics Workspace - update to 2.0.93
python-bleach (Red Hat package) - addressed in versions 3.3.0-1.el7pc, 3.3.0-1.el8pc
QRadar User Behavior Analytics - update to 4.1.11
automation-hub (Red Hat package) - addressed in versions 4.2.2-1.el7pc, 4.2.2-1.el8pc
python-galaxy-ng (Red Hat package) - addressed in versions 4.2.2-1.el7pc, 4.2.2-1.el8pc
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202301121031
rh-nodejs10-nodejs (Red Hat package) - update to 10.23.1-2.el7
IBM Cognos Analytics - addressed in versions 11.2.4 FP3, 12.0.3
rh-nodejs12-nodejs (Red Hat package) - update to 12.19.1-2.el7
rh-nodejs14-nodejs (Red Hat package) - update to 14.15.4-2.el7

External References

Related Security Bulletins