CVE-2021-20086: Critical severity ibm cognos analytics vulnerability
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-bbq 1.2.1 allows a malicious user to inject properties into Object.prototype.
Other sources
jquery-bbq could allow a remote attacker to execute arbitrary code on the system, caused by a prototype pollution. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20086?
The severity of CVE-2021-20086 is high with a severity value of 8.8.
What is the description of CVE-2021-20086?
CVE-2021-20086 is a vulnerability that allows a malicious user to inject properties into Object.prototype through improperly controlled modification of object prototype attributes, also known as 'Prototype Pollution'.
What software is affected by CVE-2021-20086?
CVE-2021-20086 affects jquery-bbq version 1.2.1.
How can I fix CVE-2021-20086?
To fix CVE-2021-20086, update jquery-bbq to a version that has patched the vulnerability.
Where can I find more information about CVE-2021-20086?
More information about CVE-2021-20086 can be found at the following reference: [https://github.com/BlackFan/client-side-prototype-pollution/blob/master/pp/jquery-bbq.md](https://github.com/BlackFan/client-side-prototype-pollution/blob/master/pp/jquery-bbq.md)