CVE-2022-22143

HIGH8.4EPSS 1.7%

Prototype Pollution in convict

發布日:2022/4/20修改日:2026/3/13

描述

### Impact * An attacker can inject attributes that are used in other components * An attacker can override existing attributes with ones that have incompatible type, which may lead to a crash. The main use case of Convict is for handling server-side configurations written by the admins owning the servers, and not random users. So it's unlikely that an admin would deliberately sabotage their own server. Still a situation can happen where an admin not knowledgeable about JavaScript could be tricked by an attacker into writing the malicious JavaScript code into some config files. ### Patches The problem is patched in `[email protected]`. Users should upgrade to `[email protected]`. ### Workarounds No way for users to fix or remediate the vulnerability without upgrading ### References * https://www.huntr.dev/bounties/1-npm-convict/ * #384 * 3b86be087d8f14681a9c889d45da7fe3ad9cd880 * 1ea0ab19c5208f66509e1c43b0d0f21c1fd29b75 ### For more information If you have any questions or comments about this advisory: add your question as a comment in #384

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH8.4CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

參考連結(9)