CVE-2022-25904
Summary
| CVE | CVE-2022-25904 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-20 05:15:00 UTC |
| Updated | 2022-12-29 18:43:00 UTC |
| Description | All versions of package safe-eval are vulnerable to Prototype Pollution which allows an attacker to add or modify properties of the Object.prototype.Consolidate when using the function safeEval. This is because the function uses vm variable, leading an attacker to modify properties of the Object.prototype. |
Risk And Classification
Problem Types: CWE-1321
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Safe-eval Project | Safe-eval | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Prototype pollution in function safeEval in the file index.js · Issue #26 · hacksparrow/safe-eval · GitHub | CONFIRM | github.com | |
| Prototype Pollution in safe-eval | CVE-2022-25904 | Snyk | CONFIRM | security.snyk.io | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Yuhan Gao
There are currently no legacy QID mappings associated with this CVE.