Lucene search

K
osvGoogleOSV:CVE-2022-25878
HistoryMay 27, 2022 - 8:15 p.m.

CVE-2022-25878

2022-05-2720:15:10
Google
osv.dev
8

0.001 Low

EPSS

Percentile

50.6%

The package protobufjs before 6.11.3 are vulnerable to Prototype Pollution which can allow an attacker to add/modify properties of the Object.prototype. This vulnerability can occur in multiple ways: 1. by providing untrusted user input to util.setProperty or to ReflectionObject.setParsedOption functions 2. by parsing/loading .proto files

0.001 Low

EPSS

Percentile

50.6%