跳转到帖子

A security related issue has been fixed which impacted one of the third party libraries being used in Admin User Inferface.

recommended_posts

发布于
  • Members

A security related issue has been fixed which impacted one of the third party libraries being used in Admin User Inferface.

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
01/20/2025
Created
01/16/2025
Added
01/20/2025
Modified
01/21/2025

Description

This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing options (or the defaults options) are deeply merged with provided options. However, during this operation, the keys of the object being set are not checked, leading to a prototype pollution.

Solution(s)

  • zimbra-collaboration-upgrade-latest

References

  • https://attackerkb.com/topics/cve-2020-7746
  • CVE - 2020-7746
  • https://snyk.io/vuln/SNYK-JS-CHARTJS-1018716
  • https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1019374
  • https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1019375
  • https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBCHARTJS-1019376
  • https://github.com/chartjs/Chart.js/pull/7920
  • 查看数 716
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…