« Volver al listado

CVE-2019-10798

Estado: ModificadaMedia (5.3)—

rdf-graph-array through 0.3.0-rc6 manipulation of JavaScript objects resutling in Prototype Pollution. The rdf.Graph.prototype.add method could be tricked into adding or modifying properties of Object.prototype.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-10798",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "report@snyk.io",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "rdf-graph-array",
          "versions": [
            {
              "status": "affected",
              "version": "All versions including 0.3.0-rc6"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-02-24T18:15:15.227",
  "references": [
    {
      "url": "https://github.com/rdf-ext-archive/rdf-graph-array/blob/master/index.js#L211",
      "tags": [
        "Exploit",
        "Tool Signature"
      ],
      "source": "report@snyk.io"
    },
    {
      "url": "https://snyk.io/vuln/SNYK-JS-RDFGRAPHARRAY-551803",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "report@snyk.io"
    },
    {
      "url": "https://github.com/rdf-ext-archive/rdf-graph-array/blob/master/index.js#L211",
      "tags": [
        "Exploit",
        "Tool Signature"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://snyk.io/vuln/SNYK-JS-RDFGRAPHARRAY-551803",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "rdf-graph-array through 0.3.0-rc6 manipulation of JavaScript objects resutling in Prototype Pollution. The rdf.Graph.prototype.add method could be tricked into adding or modifying properties of Object.prototype."
    },
    {
      "lang": "es",
      "value": "rdf-graph-array versiones hasta 0.3.0-rc6, la manipulación de objetos JavaScript resultando en una Prototype Pollution. El método rdf.Graph.prototype.add podría ser engañado para agregar o modificar propiedades de Object.prototype."
    }
  ],
  "lastModified": "2026-06-17T02:11:41.640",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:rdf-graph-array_project:rdf-graph-array:0.3.0:-:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "00614B18-1C07-4391-8703-237FD6CA504B"
            },
            {
              "criteria": "cpe:2.3:a:rdf-graph-array_project:rdf-graph-array:0.3.0:rc1:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "77CBF58D-8901-42FD-8BA5-765ABC4702B6"
            },
            {
              "criteria": "cpe:2.3:a:rdf-graph-array_project:rdf-graph-array:0.3.0:rc6:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2935C82C-8C1F-4DC9-B4E5-3917505C4D98"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "report@snyk.io"
}