Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-21803

Опубликовано: 12 апр. 2022
Источник: nvd
CVSS3: 7.3
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

This affects the package nconf before 0.11.4. When using the memory engine, it is possible to store a nested JSON representation of the configuration. The .set() function, that is responsible for setting the configuration properties, is vulnerable to Prototype Pollution. By providing a crafted property, it is possible to modify the properties on the Object.prototype.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nconf_project:nconf:*:*:*:*:*:node.js:*:*
Версия до 0.11.4 (исключая)

EPSS

Процентиль: 64%
0.00478
Низкий

7.3 High

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-1321

Связанные уязвимости

CVSS3: 7.3
redhat
почти 4 года назад

This affects the package nconf before 0.11.4. When using the memory engine, it is possible to store a nested JSON representation of the configuration. The .set() function, that is responsible for setting the configuration properties, is vulnerable to Prototype Pollution. By providing a crafted property, it is possible to modify the properties on the Object.prototype.

CVSS3: 7.3
github
почти 4 года назад

Prototype Pollution in nconf

EPSS

Процентиль: 64%
0.00478
Низкий

7.3 High

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-1321