Prototype pollution in json-bigint npm package < 1.0.0 may lead to a denial-of-service (DoS) attack. It allows to cause denial of service using very limited input (~70 bytes). References: https://hackerone.com/reports/916430
Statement: In Red Hat Openshift Container Storage 4 the noobaa-core container includes the affected version of json-bigint as a dependency of googleapis, however the json-bigint library is not being used and hence this issue has been rated as having a security impact of Low.
External References: https://hackerone.com/reports/916430
Upstream fix: https://github.com/sidorares/json-bigint/commit/c85a4300aa0159ce1859c1b1adfdac9e515e5396
This issue has been addressed in the following products: Red Hat OpenShift Container Storage 4.6.0 on RHEL-8 Via RHSA-2020:5605 https://access.redhat.com/errata/RHSA-2020:5605
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-8237