{
  "threat_severity" : "Low",
  "public_date" : "2018-02-15T00:00:00Z",
  "bugzilla" : {
    "description" : "hoek: Prototype pollution in utilities function",
    "id" : "1545893",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1545893"
  },
  "cvss3" : {
    "cvss3_base_score" : "2.9",
    "cvss3_scoring_vector" : "CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
    "status" : "verified"
  },
  "cwe" : "CWE-20",
  "details" : [ "hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge' and 'applyToDefaults' functions, which allows a malicious user to modify the prototype of \"Object\" via __proto__, causing the addition or modification of an existing property that will exist on all objects." ],
  "statement" : "Red Hat Quay includes hoek as a dependency of protractor which is only used at build time. The vulnerable library is not used at runtime meaning this has a low impact on Red Hat Quay.",
  "affected_release" : [ {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "fh-system-dump-tool-0:1.0.0-5.el7"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "fping-0:3.10-4.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "nagios-0:4.0.8-8.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "nagios-plugins-0:2.0.3-3.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "perl-Crypt-CBC-0:2.33-2.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "perl-Crypt-DES-0:2.05-20.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "perl-Net-SNMP-0:6.0.1-7.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "phantomjs-0:1.9.7-3.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "python-meld3-0:0.6.10-1.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "qstat-0:2.11-13.20080912svn311.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "radiusclient-ng-0:0.5.6-9.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "redis-0:2.8.21-2.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap-fh-openshift-templates-0:4.6.0-5.el7"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap-mod_authnz_external-0:3.3.1-7.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "sendEmail-0:1.56-2.el7"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "ssmtp-0:2.64-14.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1263",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "supervisor-0:3.1.3-3.el7map"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/fh-aaa:1.1.3-4"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/fh-appstore:2.1.2-3"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/fh-mbaas:6.0.3-2"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/fh-messaging:3.2.0-4"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/fh-metrics:3.2.0-5"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/fh-ngui:5.19.3-1"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/fh-scm:1.1.4-2"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/fh-sdks:1.0.0-36"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/fh-statsd:2.1.3-4"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/fh-supercore:5.0.10-2"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/gitlab-shell:2.1.2-16"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/httpd:2.4-47"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/installer:1.0.0-42"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/memcached:1.4.15-32"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/millicore:7.55.0-4"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/mongodb:3.2-36"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/mysql:5.5-28"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/nagios:4.0.8-58"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/redis:2.8.21-40"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/ups-eap:1.1.4-35"
  }, {
    "product_name" : "Red Hat Mobile Application Platform 4.6",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1264",
    "cpe" : "cpe:/a:redhat:mobile_application_platform:4.6",
    "package" : "rhmap46/wildcard-proxy:1.0.0-17"
  }, {
    "product_name" : "Red Hat Quay 3",
    "release_date" : "2021-10-19T00:00:00Z",
    "advisory" : "RHSA-2021:3917",
    "cpe" : "cpe:/a:redhat:quay:3::el8",
    "package" : "quay/quay-rhel8:v3.6.0-62",
    "impact" : "low"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Will not fix",
    "package_name" : "nodejs-hoek",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat OpenShift Enterprise 3",
    "fix_state" : "Will not fix",
    "package_name" : "nodejs-hoek",
    "cpe" : "cpe:/a:redhat:openshift:3"
  }, {
    "product_name" : "Red Hat Software Collections",
    "fix_state" : "Will not fix",
    "package_name" : "rh-nodejs4-nodejs-hoek",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:3"
  }, {
    "product_name" : "Red Hat Software Collections",
    "fix_state" : "Will not fix",
    "package_name" : "rh-nodejs6-nodejs-hoek",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:3"
  }, {
    "product_name" : "Red Hat Virtualization 4",
    "fix_state" : "Not affected",
    "package_name" : "ovirt-engine-api-explorer",
    "cpe" : "cpe:/o:redhat:rhev_hypervisor:4"
  }, {
    "product_name" : "Red Hat Virtualization 4",
    "fix_state" : "Not affected",
    "package_name" : "ovirt-engine-dashboard",
    "cpe" : "cpe:/o:redhat:rhev_hypervisor:4"
  }, {
    "product_name" : "Red Hat Virtualization 4",
    "fix_state" : "Not affected",
    "package_name" : "ovirt-engine-ui-extensions",
    "cpe" : "cpe:/o:redhat:rhev_hypervisor:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2018-3728\nhttps://nvd.nist.gov/vuln/detail/CVE-2018-3728" ],
  "name" : "CVE-2018-3728",
  "csaw" : false
}