CVE-2023-0163

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/11/2024
Last modified:
15/10/2025

Description

Improperly Controlled Modification of Object Prototype Attributes (&amp;#39;Prototype Pollution&amp;#39;) vulnerability in Mozilla Convict.<br /> <br /> This allows an attacker to inject attributes that are used in other components, or to override existing attributes with ones that have incompatible type, which may lead to a crash.<br /> <br /> <br /> The main use case of Convict is for handling server-side <br /> configurations written by the admins owning the servers, and not random <br /> users. So it&amp;#39;s unlikely that an admin would deliberately sabotage their <br /> own server. Still, a situation can happen where an admin not <br /> knowledgeable about JavaScript could be tricked by an attacker into <br /> writing the malicious JavaScript code into some config files.<br /> <br /> <br /> <br /> This issue affects Convict: before 6.2.4.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:convict:*:*:*:*:*:node.js:*:* 6.2.4 (excluding)