CVE-2022-22143: Prototype Pollution
Published May 1, 2022
·Updated
The package convict before 6.2.2 are vulnerable to Prototype Pollution via the convict function due to missing validation of parentKey. Note: This vulnerability derives from an incomplete fix of another vulnerability
Affected Software
1 affected component
Mozilla Convict Node.js<6.2.2
Remediation
Patch Available
Event History
May 1, 2022
CVE Published
via MITRE·03:30 PM
Data Sourced
via MITRE·03:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-22143?
CVE-2022-22143 is considered to have a moderate severity due to the potential for prototype pollution.
2
How do I fix CVE-2022-22143?
To remediate CVE-2022-22143, update the convict package to version 6.2.2 or higher.
3
Who is impacted by CVE-2022-22143?
Applications using the convict package below version 6.2.2 are vulnerable to CVE-2022-22143.
4
What type of vulnerability is CVE-2022-22143?
CVE-2022-22143 is classified as a Prototype Pollution vulnerability.
5
What package is affected by CVE-2022-22143?
The convict package before version 6.2.2 is affected by CVE-2022-22143.