#VU64696 Input validation error in nconf - CVE-2022-21803
Published: June 27, 2022 / Updated: June 29, 2022
nconf
indexzero
Description
The vulnerability allows a remote attacker to modify files on the system.
The vulnerability exists due to .set() function that is responsible for setting the configuration properties is vulnerable to Prototype Pollution. A remote attacker can provide a specially crafted property, leading to prototype object pollution.