Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35067
HistoryApr 13, 2022 - 3:18 a.m.

Prototype Pollution

2022-04-1303:18:28
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.001 Low

EPSS

Percentile

47.8%

nconf is vulnerable to prototype pollution. The function prototype.set() allows an attacker to get control of value of “path” and modify attributes such as __proto__, constructor and prototype.

CPENameOperatorVersion
nconfle0.11.3
nconfle0.10.0
nconfle0.11.3
nconfle0.10.0

0.001 Low

EPSS

Percentile

47.8%