Candidate: CVE-2020-7720 PublicDate: 2020-09-01 10:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7720 https://snyk.io/vuln/SNYK-JS-NODEFORGE-598677 https://github.com/digitalbazaar/forge/commit/6a1e3ef74f6eb345bcff1b82184201d1e28b6756 https://github.com/digitalbazaar/forge/blob/master/CHANGELOG.md https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-609293 Description: The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L [7.3 HIGH] Patches_node-node-forge: upstream_node-node-forge: needs-triage precise/esm_node-node-forge: DNE trusty_node-node-forge: ignored (out of standard support) trusty/esm_node-node-forge: DNE xenial_node-node-forge: DNE bionic_node-node-forge: DNE focal_node-node-forge: needs-triage groovy_node-node-forge: not-affected (0.10.0~dfsg-1) hirsute_node-node-forge: not-affected (0.10.0~dfsg-1) impish_node-node-forge: not-affected (0.10.0~dfsg-1) jammy_node-node-forge: not-affected (0.10.0~dfsg-1) devel_node-node-forge: not-affected (0.10.0~dfsg-1)