← back
CVE-2022-41714

fastest-json-copy 1.0.1 - Prototype Pollution

CVSS 5.3 MEDIUMEPSS 0.6%CWE-1321
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.3EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
03 Nov 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
fastest-json-copy version 1.0.1 allows an external attacker to edit or add new properties to an object. This is possible because the application does not correctly validate the incoming JSON keys, thus allowing the '__proto__' property to be edited.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected products
n/a · fastest-json-copy

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →