CVE-2020-28458: Prototype Pollution
All versions of package datatables.net are vulnerable to Prototype Pollution due to an incomplete fix for https://snyk.io/vuln/SNYK-JS-DATATABLESNET-598806.
Other sources
Node.js datatables.net module could allow a remote attacker to execute arbitrary code on the system, caused by a prototype pollution flaw. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
— IBM
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-28458?
CVE-2020-28458 is a vulnerability in the Node.js datatables.net module that allows a remote attacker to execute arbitrary code on the system.
How does CVE-2020-28458 work?
CVE-2020-28458 exploits a prototype pollution flaw in the datatables.net module by sending a specially-crafted request, allowing the attacker to execute arbitrary code.
What is the severity of CVE-2020-28458?
CVE-2020-28458 has a severity rating of 7.3 (High).
Which versions of datatables.net are affected by CVE-2020-28458?
All versions up to and excluding 1.10.23 of the datatables.net module are affected by CVE-2020-28458.
How can I fix CVE-2020-28458?
To fix CVE-2020-28458, update to version 1.10.23 of the datatables.net module.