CVE-2020-7720: Prototype Pollution
A flaw was found in nodejs-node-forge. A Prototype Pollution via the util.setPath function is possible.
Other sources
All versions of package node-forge before 0.10.0 are vulnerable to Prototype Pollution via the util.setPath function.
References: https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-609293 https://snyk.io/vuln/SNYK-JS-NODEFORGE-598677
— Red Hat
The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: version 0.10.0 is a breaking change removing the vulnerable functions.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-7720?
CVE-2020-7720 has been classified as a medium severity vulnerability due to Prototype Pollution risks.
How do I fix CVE-2020-7720?
To fix CVE-2020-7720, you should upgrade to node-forge version 0.10.0 or later.
Which versions of node-forge are affected by CVE-2020-7720?
All versions of node-forge before 0.10.0 are affected by CVE-2020-7720.
What does CVE-2020-7720 affect?
CVE-2020-7720 affects the nodejs-node-forge package and its prototype pollution vulnerability.
Can CVE-2020-7720 be exploited?
Yes, CVE-2020-7720 can be exploited through the util.setPath function leading to potential security issues.