PT-2020-6496 · Unknown · Datatables.Net
Published
2020-10-25
·
Updated
2025-07-30
·
CVE-2020-28458
CVSS v2.0
7.5
7.5
High
Base vector | Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
datatables.net (affected versions not specified)
Description:
The issue is related to insufficient control of modification of dynamically defined object properties, which can be exploited by a remote attacker to execute arbitrary code or cause a denial of service. The vulnerability is due to an incomplete fix for a previously known issue.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Prototype Pollution
Resource Exhaustion
Related Identifiers
BDU:2021-05423
CVE-2020-28458
GHSA-M7J4-FHG6-XF5V
RHSA-2021:1169
RHSA-2021:1184
RHSA-2021:1186
SNYK-JAVA-ORGWEBJARSBOWER-1051961
SNYK-JAVA-ORGWEBJARSNPM-1051962
SNYK-JS-DATATABLESNET-1016402
SNYK-JS-DATATABLESNET-598806
Affected Products
Datatables.Net
References · 20
- 🔥 https://snyk.io/vuln/SNYK-JS-DATATABLESNET-598806 · Exploit
- https://github.com/DataTables/DataTablesSrc/commit/a51cbe99fd3d02aa5582f97d4af1615d11a1ea03⭐ 639 🔗 425 · Patch
- https://nvd.nist.gov/vuln/detail/CVE-2020-28458 · Security Note
- https://osv.dev/vulnerability/GHSA-m7j4-fhg6-xf5v · Vendor Advisory
- https://osv.dev/vulnerability/CVE-2020-28458 · Vendor Advisory
- https://bdu.fstec.ru/vul/2021-05423 · Security Note
- https://github.com/DataTables/DataTablesSrc⭐ 639 🔗 425 · Note
- https://github.com/418sec/huntr/pull/827⭐ 263 🔗 89 · Note
- https://github.com/DataTables/Dist-DataTables/blob/master/js/jquery.dataTables.js%23L2766⭐ 50 🔗 34 · Note
- https://snyk.io/vuln/SNYK-JS-DATATABLESNET-1016402 · Note
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28458 · Note
- https://t.me/cvenotify/84068 · Telegram Post
- https://ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-apache-and-node-js-affect-ibm-spectrum-protect-plus · Note
- https://access.redhat.com/security/cve/cve-2020-28458 · Note
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1051961 · Note