CVE-2022-22143

Published
View on NVD ↗
CVSS v3
7.5
HIGH
CVSS v2
7.5
HIGH
Affected
1
PROJECT

Description

The package convict before 6.2.2 are vulnerable to Prototype Pollution via the convict function due to missing validation of parentKey. **Note:** This vulnerability derives from an incomplete fix of another [vulnerability](https://security.snyk.io/vuln/SNYK-JS-CONVICT-1062508)

Featureful configuration management library for Node.js
GitHubGitHub
2.38K