CVE-2020-7778: Prototype Pollution
Published Nov 26, 2020
·Updated
This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an object, which can lead to executing OS commands.
Affected Software
1 affected component
systeminformation Systeminformation Node.js<4.30.2
Remediation
Event History
Nov 26, 2020
CVE Published
via MITRE·10:40 AM
Data Sourced
via MITRE·10:40 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-7778?
CVE-2020-7778 is a vulnerability in the systeminformation package before version 4.30.2 that allows an attacker to overwrite object properties and functions, potentially leading to the execution of OS commands.
2
What software is affected by CVE-2020-7778?
The systeminformation package before version 4.30.2 is affected by CVE-2020-7778.
3
How severe is CVE-2020-7778?
CVE-2020-7778 has a severity score of 7.3 (high).
4
How can CVE-2020-7778 be exploited?
CVE-2020-7778 can be exploited by an attacker overwriting the properties and functions of an object.
5
How can I fix CVE-2020-7778?
To fix CVE-2020-7778, update the systeminformation package to version 4.30.2 or later.