Prototype pollution in uPlot - CVE-2024-21489
Published: October 14, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The vulnerability exists due to improper input validation within the uplot.assign() function. A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in information disclosure or data manipulation.
Affected software
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
grafana (Red Hat package)
IBM Security QRadar Log Management AQL Plugin
How to mitigate CVE-2024-21489
IBM Security QRadar Log Management AQL Plugin - update to 1.1.1
grafana (Red Hat package) - update to 7.3.6-7.el8_4