Jordan-Hall / Jordan-Hall/angular-libs

CVE-2020-15366 (Medium) detected in ajv-6.12.0.tgz, ajv-6.9.1.tgz

Open
#15 0 comments 0 reactions 0 assignees View on GitHub
security vulnerability
Dominant language
TypeScript
Stars
0
Forks
0
PR merge metrics
No merged PRs in 30d

Description

## CVE-2020-15366 - Medium Severity Vulnerability
Vulnerable Libraries - ajv-6.12.0.tgz, ajv-6.9.1.tgz


ajv-6.12.0.tgz

Another JSON Schema Validator


Library home page: https://registry.npmjs.org/ajv/-/ajv-6.12.0.tgz


Path to dependency file: angular-libs/package.json


Path to vulnerable library: angular-libs/node_modules/@angular-devkit/build-angular/node_modules/ajv/package.json,angular-libs/node_modules/@ngtools/webpack/node_modules/ajv/package.json,angular-libs/node_modules/@angular-devkit/build-webpack/node_modules/ajv/package.json,angular-libs/node_modules/@angular/cli/node_modules/ajv/package.json,angular-libs/node_modules/@schematics/update/node_modules/ajv/package.json


Dependency Hierarchy:
- build-angular-0.901.0.tgz (Root Library)
- :x: **ajv-6.12.0.tgz** (Vulnerable Library)


ajv-6.9.1.tgz

Another JSON Schema Validator


Library home page: https://registry.npmjs.org/ajv/-/ajv-6.9.1.tgz


Path to dependency file: angular-libs/package.json


Path to vulnerable library: angular-libs/node_modules/@nestjs/schematics/node_modules/ajv/package.json


Dependency Hierarchy:
- schematics-6.9.4.tgz (Root Library)
- core-7.3.8.tgz
- :x: **ajv-6.9.1.tgz** (Vulnerable Library)

Found in HEAD commit: 9488e30000c55115bdcf2c761e36ebc51f5a3f28


Found in base branch: master



Vulnerability Details



An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an untrusted schema should be a denial of service, not execution of code.)

Publish Date: 2020-07-15

URL: CVE-2020-15366



CVSS 3 Score Details (5.6)

Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: Low


For more information on CVSS3 Scores, click here.


Suggested Fix

Type: Upgrade version


Origin: https://github.com/ajv-validator/ajv/releases/tag/v6.12.3


Release Date: 2020-07-15


Fix Resolution: ajv - 6.12.3

***
Step up your Open Source Security Game with WhiteSource [here](https://www.whitesourcesoftware.com/full_solution_bolt_github)

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.