CVE-2022-41713
deep-object-diff 1.1.0 - Prototype Pollution
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.3EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
03 Nov 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
deep-object-diff version 1.1.0 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the '__proto__' property to be edited.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected products
n/a · deep-object-diffWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →