Prototype pollution in DataTables - CVE-2020-28458
Published: September 12, 2022 / Updated: October 22, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The vulnerability exists due to improper input validation. A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in information disclosure or data manipulation.
Affected software
Planning Analytics Local
IBM Cognos Analytics
Tenable Nessus
How to mitigate CVE-2020-28458
Tenable Nessus - addressed in versions 10.3.1, 10.5.0
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2
Links to Public Exploits and PoC-codes
External References
- https://github.com/DataTables/Dist-DataTables/blob/master/js/jquery.dataTables.js%23L2766
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1051961
- https://github.com/DataTables/DataTablesSrc/commit/a51cbe99fd3d02aa5582f97d4af1615d11a1ea03
- https://snyk.io/vuln/SNYK-JS-DATATABLESNET-1016402
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1051962
- https://snyk.io/vuln/SNYK-JS-DATATABLESNET-598806