CVE-2020-7608: Medium severity yargs-parser vulnerability
A vulnerability was found in nodesjs-yargs-parser, where it can be tricked into adding or modifying properties of the Object.prototype using a "proto" payload. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Other sources
A vulnerability was found in yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "proto" payload.
Reference: https://snyk.io/vuln/SNYK-JS-YARGSPARSER-560381
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2020-7608.
What is the severity of CVE-2020-7608?
The severity of CVE-2020-7608 is critical with a score of 9.8.
What is the affected software for CVE-2020-7608?
The affected software for CVE-2020-7608 includes yargs-parser module versions up to 13.1.2, 15.0.1, and 18.1.1. Additionally, Node.js versions up to 10.23.0, 12.19.0, and 14.9.0 are also affected.
How can I fix CVE-2020-7608?
To fix CVE-2020-7608, upgrade the yargs-parser module to version 13.1.2, 15.0.1, or 18.1.1. Additionally, upgrade Node.js to version 10.23.0, 12.19.0, or 14.9.0.
What is the reference for CVE-2020-7608?
The references for CVE-2020-7608 are: [1] https://snyk.io/vuln/SNYK-JS-YARGSPARSER-560381, [2] https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1840005, [3] https://github.com/yargs/yargs-parser/commit/63810ca1ae1a24b08293a4d971e70e058c7a41e2