PT-2022-23904 · Stealjs · Stealjs

Secdevlpr26

·

Published

2022-09-15

·

Updated

2022-09-19

·

CVE-2022-37264

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions stealjs steal version 2.2.4
Description The issue is related to a prototype pollution vulnerability. It affects stealjs steal via the optionName variable in main.js.
Recommendations For stealjs steal version 2.2.4, consider restricting access to the optionName variable in main.js to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2022-37264
GHSA-8F8G-9J73-7P82

Affected Products

Stealjs