Lucene search

K
osvGoogleOSV:GHSA-6XWR-Q98W-RVG7
HistoryApr 13, 2022 - 12:00 a.m.

Prototype Pollution in nconf

2022-04-1300:00:30
Google
osv.dev
13
nconf
memory engine
nested json
configuration
set function
vulnerability
prototype pollution
object.prototype

EPSS

0.002

Percentile

53.3%

nconf before 0.11.4. When using the memory engine, it is possible to store a nested JSON representation of the configuration. The .set() function, that is responsible for setting the configuration properties, is vulnerable to Prototype Pollution. By providing a crafted property, it is possible to modify the properties on the Object.prototype.

EPSS

0.002

Percentile

53.3%