CVE Vulnerabilities

CVE-2019-18841

Published: Nov 11, 2019 | Modified: Aug 24, 2020
CVSS 3.x
7.3
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Chartkick.js 3.1.0 through 3.1.3, as used in the Chartkick gem before 3.3.0 for Ruby, allows prototype pollution.

Affected Software

Name Vendor Start Version End Version
Chartkick.js Chartkick 3.1.0 (including) 3.1.3 (including)

References