CVE-2020-7743 Information

Description

The package mathjs before 7.5.1 are vulnerable to Prototype Pollution via the deepExtend function that runs upon configuration updates.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Reference

https://github.com/josdejong/mathjs/blob/develop/src/utils/object.js23L82 https://github.com/josdejong/mathjs/commit/ecb80514e80bce4e6ec7e71db8ff79954f07c57e https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1017113 https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1017112 https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1017111 https://snyk.io/vuln/SNYK-JS-MATHJS-1016401

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

LOW

Base Severity

7.3

Share on: