PT-2022-24027 · Unknown · Mockery.Js

Secdevlpr26

·

Published

2022-10-12

·

Updated

2025-05-15

·

CVE-2022-37614

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions mockery.js (affected versions not specified)
Description The issue is related to a prototype pollution vulnerability in the enable function of mockery.js, specifically in the mfncooper mockery commit 822f0566fd6d72af8c943ae5ca2aa92e516aa2cf. This vulnerability is exploited via the key variable in mockery.js.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2022-37614
GHSA-GMWP-3PWC-3J3G

Affected Products

Mockery.Js