ZeroHour

CVE-2022-21824

CVSS 3.1
8.2 high
EPSS
22%p97
Published
()
Modified
Description

Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first parameter, which could be "__proto__". The prototype pollution has very limited control, in that it only allows an empty string to be assigned to numerical keys of the object prototype.Node.js >= 12.22.9, >= 14.18.3, >= 16.13.2, and >= 17.3.1 use a null protoype for the object these properties are being assigned to.

Vendors
nodejsoracledebiannetapp
Products
node.js, mysql cluster, mysql connectors, mysql enterprise monitor, mysql server, mysql workbench, peoplesoft enterprise peopletools, debian linux, oncommand insight, oncommand workflow automation, snapcenter
Weakness
CWE-471, CWE-1321
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

In the news

No ingested article mentions this CVE yet.