Candidate: CVE-2020-7751 PublicDate: 2020-10-26 12:17:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7751 https://snyk.io/vuln/SNYK-JS-PATHVAL-596926 https://github.com/chaijs/pathval/pull/58 Description: pathval before version 1.1.1 is vulnerable to prototype pollution. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=972895 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H [7.2 HIGH] Patches_node-pathval: upstream_node-pathval: released (1.1.0-4) precise/esm_node-pathval: DNE trusty_node-pathval: ignored (out of standard support) trusty/esm_node-pathval: DNE xenial_node-pathval: DNE bionic_node-pathval: needs-triage focal_node-pathval: needs-triage groovy_node-pathval: ignored (reached end-of-life) hirsute_node-pathval: not-affected (1.1.0-4) impish_node-pathval: not-affected (1.1.0-4) jammy_node-pathval: not-affected (1.1.0-4) devel_node-pathval: not-affected (1.1.0-4)