First published: Tue Sep 10 2024(Updated: )
All versions of the package node-gettext are vulnerable to Prototype Pollution via the addTranslations() function in gettext.js due to improper user input sanitization.
Affected Software | Affected Version | How to fix |
---|---|---|
gettext | <= |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability REDHAT-BUG-2311014 is classified as a moderate severity issue.
To remediate REDHAT-BUG-2311014, update the node-gettext package to the latest version that includes the patch.
The impacts of REDHAT-BUG-2311014 include the risk of prototype pollution, which can lead to arbitrary code execution or application behavior manipulation.
All versions of the node-gettext package are affected by the vulnerability REDHAT-BUG-2311014.
The addTranslations() function in gettext.js is the component vulnerable to prototype pollution in REDHAT-BUG-2311014.