Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-22143

Опубликовано: 01 мая 2022
Источник: redhat
CVSS3: 9.8

Описание

The package convict before 6.2.2 are vulnerable to Prototype Pollution via the convict function due to missing validation of parentKey. Note: This vulnerability derives from an incomplete fix of another vulnerability

A flaw was found in convict. This flaw allows an attacker to inject attributes used in other components and override existing attributes with ones that have an incompatible type, leading to a crash.

Отчет

The convict package is a transitive dependency and is not used directly in the Red Hat Advanced Cluster Security product. Hence, it is categorized as a Moderate impact.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-docs-rhel8Not affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-main-rhel8Not affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-rhel8-operatorNot affected
Red Hat Advanced Cluster Security 3advanced-cluster-security/rhacs-roxctl-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1321
https://bugzilla.redhat.com/show_bug.cgi?id=2080845convict: Prototype Pollution in convict

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 4 года назад

The package convict before 6.2.2 are vulnerable to Prototype Pollution via the convict function due to missing validation of parentKey. **Note:** This vulnerability derives from an incomplete fix of another [vulnerability](https://security.snyk.io/vuln/SNYK-JS-CONVICT-1062508)

CVSS3: 8.4
github
почти 4 года назад

Prototype Pollution in convict

9.8 Critical

CVSS3