漏洞信息详情
Yargs Y18n 输入验证错误漏洞
漏洞简介
Yargs Y18n是Yargs个人开发者的一个类似I18n的由Js编写的代码库。
y18n before 3.2.2, 4.0.1 and 5.0.5版本存在输入验证错误漏洞,该漏洞源于网络系统或产品未对输入的数据进行正确的验证。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/yargs/y18n/pull/108
参考网址
来源:MISC
链接:https://github.com/yargs/y18n/pull/108
来源:MISC
链接:https://snyk.io/vuln/SNYK-JS-Y18N-1021887
来源:MISC
链接:https://github.com/yargs/y18n/issues/96
来源:MISC
链接:https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1038306
来源:MISC
链接:https://www.oracle.com/security-alerts/cpuApr2021.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160528/Red-Hat-Security-Advisory-2020-5499-01.html
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-security-vulnerabilities-in-ibm-sdk-for-node-js-might-affect-the-configuration-editor-used-by-ibm-business-automation-workflow-and-business-process-manager-bpm/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-potential-vulnerability-with-node-js-5/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-cloud-pak-for-security-contains-security-vulnerabilities/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-node-js-affect-ibm-app-connect-enterprise-and-ibm-integration-bus-cve-2020-7774/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3227
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4264/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-prototype-pollution-flaw-in-y18n-in-ibm-datapower-gateway/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-a-security-vulnerability-in-node-js-y18n-module-affects-ibm-cloud-pak-for-multicloud-management/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/161287/Red-Hat-Security-Advisory-2021-0421-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/160294/Red-Hat-Security-Advisory-2020-5305-01.html
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-a-security-vulnerability-in-node-js-y18n-module-affects-ibm-cloud-automation-manager/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0587
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4441/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2408
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-7774
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162699/Red-Hat-Security-Advisory-2021-2041-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2649
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6412225
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1757
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-multiple-vulnerabilities-affect-ibm-cloud-pak-for-automation/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163690/Red-Hat-Security-Advisory-2021-2438-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0692
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2555
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021092814
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Node-js-y18n-privilege-escalation-via-Prototype-Pollution-34015
受影响实体
暂无
补丁
- Yargs Y18n 输入验证错误漏洞的修复措施<!--2020-11-17-->
还没有评论,来说两句吧...