Candidate: CVE-2019-10768 PublicDate: 2019-11-19 21:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10768 https://snyk.io/vuln/SNYK-JS-ANGULAR-534884 Description: In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload. Ubuntu-Description: Notes: Mitigation: Bugs: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=945249 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_angular.js: upstream: https://github.com/angular/angular.js/commit/add78e62004e80bb1e16ab2dfe224afa8e513bc3 upstream_angular.js: needs-triage precise/esm_angular.js: DNE trusty_angular.js: ignored (out of standard support) trusty/esm_angular.js: DNE xenial_angular.js: not-affected (code not present) esm-infra/xenial_angular.js: not-affected (code not present) bionic_angular.js: needed disco_angular.js: ignored (reached end-of-life) eoan_angular.js: ignored (reached end-of-life) focal_angular.js: not-affected (1.7.9-1) groovy_angular.js: not-affected (1.7.9-1) hirsute_angular.js: not-affected (1.7.9-1) impish_angular.js: not-affected (1.7.9-1) jammy_angular.js: not-affected (1.7.9-1) devel_angular.js: not-affected (1.7.9-1)