CVE-2022-21824
high · 8.2Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first parameter, which could be "__proto__". The prototype pollution has very limited control, in that it only allows an empty string to be assigned to numerical keys of the object prototype.Node.js >= 12.22.9, >= 14.18.3, >= 16.13.2, and >= 17.3.1 use a null protoype for the object these properties are being assigned to.
8.2
CVSS
21.5%
EPSS (exploit prob.)
98th
EPSS percentile
2022-02-24
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Weaknesses
CWE-471CWE-1321
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| nodejs | node.js | >= 12.0.0, < 12.22.9 |
| nodejs | node.js | >= 14.0.0, < 14.18.3 |
| nodejs | node.js | >= 16.0.0, < 16.13.2 |
| nodejs | node.js | >= 17.0.0, < 17.3.1 |
| oracle | mysql_cluster | <= 8.0.29 |
| oracle | mysql_connectors | <= 8.0.28 |
| oracle | mysql_enterprise_monitor | <= 8.0.29 |
| oracle | mysql_server | <= 8.0.29 |
| oracle | mysql_workbench | <= 8.0.28 |
| oracle | peoplesoft_enterprise_peopletools | 8.58 |
| oracle | peoplesoft_enterprise_peopletools | 8.59 |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 11.0 |
| netapp | oncommand_insight | all versions |
| netapp | oncommand_workflow_automation | all versions |
| netapp | snapcenter | all versions |
Check a specific version with /api/v1/cve/match.
References
- https://hackerone.com/reports/1431042
- https://lists.debian.org/debian-lts-announce/2022/10/msg00006.html
- https://nodejs.org/en/blog/vulnerability/jan-2022-security-releases/
- https://security.netapp.com/advisory/ntap-20220325-0007/
- https://security.netapp.com/advisory/ntap-20220729-0004/
- https://www.debian.org/security/2022/dsa-5170
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://hackerone.com/reports/1431042
- https://lists.debian.org/debian-lts-announce/2022/10/msg00006.html
- https://nodejs.org/en/blog/vulnerability/jan-2022-security-releases/
- https://security.netapp.com/advisory/ntap-20220325-0007/
- https://security.netapp.com/advisory/ntap-20220729-0004/
- https://www.debian.org/security/2022/dsa-5170
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-21824