CVE-2020-7774: high-severity vulnerability in y18n
Prototype Pollution
Published · Updated
33Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.3epss 69%
exploitation probability
69%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Affected
7 products (17 components)
OpenShift Service Mesh 1 · Red Hat Openshift Data Foundation 4 · OpenShift Service Mesh 2.0 · Red Hat OpenShift Container Platform 4 · Red Hat Advanced Cluster Management for Kubernetes 2 · and others 2
none_available: Affected
Fixed
8 products (243 components)
Red Hat Enterprise Linux AppStream (v. 8) · Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) · Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) · Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) · Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) · and others 3
Not affected
6 products (794 components) — because the vulnerable code is not present in the product
Red Hat OpenShift Container Platform 4.7 · Red Hat OpenShift Container Platform 4.8 · Red Hat OpenShift Container Storage 4.7 on RHEL-8 · OpenShift Service Mesh 2.0 · Logging Subsystem for Red Hat OpenShift · and others 1
The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P
Affected products
n/a · y18n