PT-2022-26044 · Unknown · Fastest-Json-Copy

Carlos Bello

·

Published

2022-11-03

·

Updated

2025-04-29

·

CVE-2022-41714

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions fastest-json-copy version 1.0.1
Description The issue allows an external attacker to edit or add new properties to an object because the application does not correctly validate the incoming JSON keys, thus allowing the proto property to be edited.
Recommendations For fastest-json-copy version 1.0.1, consider implementing proper validation of incoming JSON keys to prevent unauthorized edits to objects, specifically restricting access to the proto property.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2022-41714
GHSA-P5G9-RJCF-95VJ

Affected Products

Fastest-Json-Copy