CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
VariantIncomplete
Description
The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-180 · CAPEC-77
CVEs mapped to this weakness (642)
page 33 of 33| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-21803 | Hig | 0.00 | 7.3 | 0.02 | Apr 12, 2022 | This affects the package nconf before 0.11.4. When using the memory engine, it is possible to store a nested JSON representation of the configuration. The .set() function, that is responsible for setting the configuration properties, is vulnerable to Prototype Pollution. By… | ||
| CVE-2022-0432 | Med | 0.00 | 6.1 | 0.04 | Feb 2, 2022 | Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0. |
- risk 0.00cvss 7.3epss 0.02
This affects the package nconf before 0.11.4. When using the memory engine, it is possible to store a nested JSON representation of the configuration. The .set() function, that is responsible for setting the configuration properties, is vulnerable to Prototype Pollution. By…
- risk 0.00cvss 6.1epss 0.04
Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0.