Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1659 | This affects the package nconf before 0.11.4. When using the memory engine, it is possible to store a nested JSON representation of the configuration. The .set() function, that is responsible for setting the configuration properties, is vulnerable to Prototype Pollution. By providing a crafted property, it is possible to modify the properties on the Object.prototype. |
Github GHSA |
GHSA-6xwr-q98w-rvg7 | Prototype Pollution in nconf |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sun, 08 Sep 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:acm:2.4::el8 cpe:/a:redhat:acm:2.5::el8 |
Mon, 19 Aug 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:acm:2.5::el8 |
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-09-16T16:53:18.553Z
Reserved: 2022-02-24T00:00:00.000Z
Link: CVE-2022-21803
No data.
Status : Modified
Published: 2022-04-12T16:15:08.480
Modified: 2024-11-21T06:45:28.023
Link: CVE-2022-21803
OpenCVE Enrichment
No data.
EUVD
Github GHSA