QID 981833
QID 981833: Nodejs (npm) Security Update for chart.js (GHSA-h68q-55jf-x68w)
This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing options (or the defaults options) are deeply merged with provided options. However, during this operation, the keys of the object being set are not checked, leading to a prototype pollution.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-h68q-55jf-x68w for updates pertaining to this vulnerability.
Vendor References
- GHSA-h68q-55jf-x68w -
github.com/advisories/GHSA-h68q-55jf-x68w
CVEs related to QID 981833
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h68q-55jf-x68w | chart.js |
|