CVE-2022-41713
Published: 03 November 2022
Summary
CVE-2022-41713 is a medium-severity Prototype Pollution (CWE-1321) vulnerability in Deep-Object-Diff Project Deep-Object-Diff. Its CVSS base score is 5.3 (Medium).
Operationally, ranked at the 33.4th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2022-7249
Vulnerability details
deep-object-diff version 1.1.0 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the '__proto__' property to be edited.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.