CVE-2022-21803
12.04.2022, 16:15
This affects the package nconf before 0.11.4. When using the memory engine, it is possible to store a nested JSON representation of the configuration. The .set() function, that is responsible for setting the configuration properties, is vulnerable to Prototype Pollution. By providing a crafted property, it is possible to modify the properties on the Object.prototype.
Vendor | Product | Version |
---|---|---|
nconf_project | nconf | 𝑥 < 0.11.4 |
𝑥
= Vulnerable software versions
References