HIGH7.3
GHSA-x2fc-mxcx-w4mf
Prototype Pollution in mathjs
Quick fix
GHSA-x2fc-mxcx-w4mf — mathjs: upgrade to the fixed version with the command below.
npm install mathjs@7.5.1Details
The package mathjs before 7.5.1 are vulnerable to Prototype Pollution via the deepExtend function that runs upon configuration updates.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-7743[ADVISORY]
- https://github.com/josdejong/mathjs/commit/ecb80514e80bce4e6ec7e71db8ff79954f07c57e[WEB]
- https://github.com/josdejong/mathjs/blob/develop/HISTORY.md#2020-10-10-version-751[WEB]
- https://github.com/josdejong/mathjs/blob/develop/src/utils/object.js%23L82[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1017113[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1017112[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1017111[WEB]
- https://snyk.io/vuln/SNYK-JS-MATHJS-1016401[WEB]
- https://www.npmjs.com/package/mathjs[WEB]