{"id":"CVE-2022-21803","aliases":["GHSA-6xwr-q98w-rvg7"],"url":"https://o3.security/vulnerability/CVE-2022-21803","summary":"Prototype Pollution","details":"This affects the package nconf before 0.11.4. When using the memory engine, it is possible to store a nested JSON representation of the configuration. The .set() function, that is responsible for setting the configuration properties, is vulnerable to Prototype Pollution. By providing a crafted property, it is possible to modify the properties on the Object.prototype.","published":"2022-04-12T15:20:12.370Z","modified":"2026-07-15T01:49:12.941811793Z","cvss":{"score":7.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"npm","name":"nconf","fixedVersion":"0.11.4"}],"fix":{"url":"https://github.com/indexzero/nconf/pull/397","label":"indexzero/nconf#397"},"references":[{"type":"WEB","url":"https://github.com/indexzero/nconf/releases/tag/v0.11.4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/21xxx/CVE-2022-21803.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-21803"},{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2632450"},{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-JS-NCONF-2395478"},{"type":"FIX","url":"https://github.com/indexzero/nconf/pull/397"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:12.941811793Z"}}