Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-25878
HistoryMay 27, 2022 - 8:15 p.m.

Design/Logic Flaw

2022-05-2720:15:00
PRIOn knowledge base
www.prio-n.com
2

8.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

50.6%

The package protobufjs before 6.11.3 are vulnerable to Prototype Pollution which can allow an attacker to add/modify properties of the Object.prototype. This vulnerability can occur in multiple ways: 1. by providing untrusted user input to util.setProperty or to ReflectionObject.setParsedOption functions 2. by parsing/loading .proto files

CPENameOperatorVersion
protobufjslt6.11.3

8.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

50.6%