SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-7746

This affects the package chart.js before 2.9.4.

CRITICAL 9.8EPSS 4.74%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (4.74%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing options (or the defaults options) are deeply merged with provided options. However, during this operation, the keys of the object being set are not checked, leading to a prototype pollution.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
4.74% probability · 91th percentile
CISA KEV
Not listed
Weakness
CWE-1321
Affected
chartjs/chart.js
Source
report@snyk.io

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.