CVE-2020-7720 describes a Prototype Pollution vulnerability in the 'node-forge' package prior to version 0.10.0, specifically within the 'util.setPath' function. This high-severity flaw (CVSS 7.3) is network-exploitable with low attack complexity and no user interaction required, potentially leading to low impacts on confidentiality, integrity, and availability. While no active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion has been observed, organizations using affected versions of 'digitalbazaar forge' should prioritize upgrading to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.10.0CPE matchmatch criteria | cpe:2.3:a:digitalbazaar:forge:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.