7.5
CVSSv3

CVE-2019-10768

Published: 19/11/2019 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

In AngularJS prior to 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

angularjs angular.js

Vendor Advisories

Debian Bug report logs - #945249 angularjs: CVE-2019-10768 Package: src:angularjs; Maintainer for src:angularjs is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 21 Nov 2019 21:18:02 UTC Severity: grave Tags: fixed-upstream, security, upstream Found in ...
Synopsis Important: Red Hat Ansible Tower 362-1 - RHEL7 Container Type/Severity Security Advisory: Important Topic Red Hat Ansible Tower 362-1 - RHEL7 Container Description Added a command to generate a new SECRET_KEY and rekey the database Removed the guest user from the optionally-co ...
Synopsis Moderate: Red Hat OpenStack Platform 1624 (python-XStatic-Angular) security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for python-XStatic-Angular is now available for Red Hat OpenStackPlatf ...
Synopsis Moderate: Red Hat OpenStack Platform 1619 (python-XStatic-Angular) security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for python-XStatic-Angular is now available for Red Hat OpenStackPlatf ...