PT-2022-14913 · Convict · Convict
Alessio Della Libera
·
Published
2022-05-13
·
Updated
2022-05-24
·
CVE-2022-21190
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
convict versions prior to 6.2.3
Description
The issue is related to a bypass of a previous security fix. It affects the
convict package and relies on manipulating the startsWith method. An attacker can bypass the security check by prepending a string value followed by a dot to dangerous paths, such as foo. proto or foo.this.constructor.prototype.Recommendations
For versions prior to 6.2.3, update to version 6.2.3 or later to resolve the issue.
Exploit
Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Convict