First published: Sun Oct 25 2020(Updated: )
Node.js datatables.net module could allow a remote attacker to execute arbitrary code on the system, caused by a prototype pollution flaw. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Credit: report@snyk.io report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/cockpit-ovirt | <0:0.14.20-1.el8e | 0:0.14.20-1.el8e |
redhat/ovirt-web-ui | <0:1.6.7-1.el8e | 0:1.6.7-1.el8e |
redhat/ovirt-engine-ui-extensions | <0:1.2.5-1.el8e | 0:1.2.5-1.el8e |
Datatables Datatables.net | <1.10.23 | |
redhat/datatables.net | <1.10.23 | 1.10.23 |
npm/datatables.net | <1.10.22 | 1.10.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2020-28458 is a vulnerability in the Node.js datatables.net module that allows a remote attacker to execute arbitrary code on the system.
CVE-2020-28458 exploits a prototype pollution flaw in the datatables.net module by sending a specially-crafted request, allowing the attacker to execute arbitrary code.
CVE-2020-28458 has a severity rating of 7.3 (High).
All versions up to and excluding 1.10.23 of the datatables.net module are affected by CVE-2020-28458.
To fix CVE-2020-28458, update to version 1.10.23 of the datatables.net module.