Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6xwr-q98w-rvg7

Опубликовано: 13 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.3

Описание

Prototype Pollution in nconf

nconf before 0.11.4. When using the memory engine, it is possible to store a nested JSON representation of the configuration. The .set() function, that is responsible for setting the configuration properties, is vulnerable to Prototype Pollution. By providing a crafted property, it is possible to modify the properties on the Object.prototype.

Пакеты

Наименование

nconf

npm
Затронутые версииВерсия исправления

< 0.11.4

0.11.4

EPSS

Процентиль: 64%
0.00478
Низкий

7.3 High

CVSS3

Дефекты

CWE-1321

Связанные уязвимости

CVSS3: 7.3
redhat
почти 4 года назад

This affects the package nconf before 0.11.4. When using the memory engine, it is possible to store a nested JSON representation of the configuration. The .set() function, that is responsible for setting the configuration properties, is vulnerable to Prototype Pollution. By providing a crafted property, it is possible to modify the properties on the Object.prototype.

CVSS3: 7.3
nvd
почти 4 года назад

This affects the package nconf before 0.11.4. When using the memory engine, it is possible to store a nested JSON representation of the configuration. The .set() function, that is responsible for setting the configuration properties, is vulnerable to Prototype Pollution. By providing a crafted property, it is possible to modify the properties on the Object.prototype.

EPSS

Процентиль: 64%
0.00478
Низкий

7.3 High

CVSS3

Дефекты

CWE-1321