Candidate: CVE-2020-7608 PublicDate: 2020-03-16 20:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7608 https://snyk.io/vuln/SNYK-JS-YARGSPARSER-560381 https://github.com/yargs/yargs-parser/commit/63810ca1ae1a24b08293a4d971e70e058c7a41e2 https://gist.github.com/Kirill89/dcd8100d010896157a36624119439832 Description: yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L [5.3 MEDIUM] Patches_node-yargs-parser: upstream_node-yargs-parser: released (18.1.1-1) precise/esm_node-yargs-parser: DNE trusty_node-yargs-parser: ignored (out of standard support) trusty/esm_node-yargs-parser: DNE xenial_node-yargs-parser: DNE bionic_node-yargs-parser: needs-triage eoan_node-yargs-parser: ignored (reached end-of-life) focal_node-yargs-parser: not-affected (18.1.1-1) groovy_node-yargs-parser: not-affected hirsute_node-yargs-parser: not-affected impish_node-yargs-parser: not-affected jammy_node-yargs-parser: not-affected devel_node-yargs-parser: not-affected