CVE-2019-18841
Summary
| CVE | CVE-2019-18841 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-11 01:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | Chartkick.js 3.1.0 through 3.1.3, as used in the Chartkick gem before 3.3.0 for Ruby, allows prototype pollution. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Chartkick | Chartkick.js | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Updated Chartkick.js to 3.2.0 · ankane/chartkick@b810936 · GitHub | CONFIRM | github.com | Patch |
| chartkick | RubyGems.org | your community gem host | MISC | rubygems.org | Product, Release Notes |
| Chartkick | MISC | chartkick.com | Product |
| chartkick/CHANGELOG.md at master · ankane/chartkick · GitHub | MISC | github.com | Product, Release Notes |
| Commits · ankane/chartkick · GitHub | MISC | github.com | Patch |
| Prototype Pollution in Chartkick.js 3.1.x · Issue #117 · ankane/chartkick.js · GitHub | MISC | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980773 Nodejs (npm) Security Update for chartkick (GHSA-5pm8-492c-92p5)