Related Vulnerabilities: CVE-2022-22143  

A flaw was found in convict. This flaw allows an attacker to inject attributes used in other components and override existing attributes with ones that have an incompatible type, leading to a crash.

Description

A flaw was found in convict. This flaw allows an attacker to inject attributes used in other components and override existing attributes with ones that have an incompatible type, leading to a crash.

Additional Information

  • Bugzilla 2080845: CVE-2022-22143 convict: Prototype Pollution in convict
  • CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
  • FAQ: Frequently asked questions about CVE-2022-22143