QID 982619
QID 982619: Nodejs (npm) Security Update for mathjs (GHSA-x2fc-mxcx-w4mf)
The package mathjs before 7.5.1 are vulnerable to Prototype Pollution via the deepExtend function that runs upon configuration updates.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-x2fc-mxcx-w4mf for updates pertaining to this vulnerability.
Vendor References
- GHSA-x2fc-mxcx-w4mf -
github.com/advisories/GHSA-x2fc-mxcx-w4mf
CVEs related to QID 982619
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-x2fc-mxcx-w4mf | mathjs |
|