HIGH · 7.7

CVE-2022-25301

All versions of package jsgui-lang-essentials are vulnerable to Prototype Pollution due to allowing all Object attributes to be altered, including their magical attributes such as proto, constructor a...

Vulnerability Description

All versions of package jsgui-lang-essentials are vulnerable to Prototype Pollution due to allowing all Object attributes to be altered, including their magical attributes such as proto, constructor and prototype.

CVSS Score

7.7

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Jsgui-Lang-Essentials ProjectJsgui-Lang-EssentialsAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-25301?

CVE-2022-25301 is a vulnerability with a CVSS score of 7.7 (HIGH). All versions of package jsgui-lang-essentials are vulnerable to Prototype Pollution due to allowing all Object attributes to be altered, including their magical attributes such as proto, constructor a...

How severe is CVE-2022-25301?

CVE-2022-25301 has been rated HIGH with a CVSS base score of 7.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-25301?

Check the references section above for vendor advisories and patch information. Affected products include: Jsgui-Lang-Essentials Project Jsgui-Lang-Essentials.