Back

HIGH

Prototype Pollution in convict

Published Nov 26, 2024

Description

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Mozilla Convict.

This allows an attacker to inject attributes that are used in other components, or to override existing attributes with ones that have incompatible type, which may lead to a crash.

The main use case of Convict is for handling server-side configurations written by the admins owning the servers, and not random users. So it's unlikely that an admin would deliberately sabotage their own server. Still, a situation can happen where an admin not knowledgeable about JavaScript could be tricked by an attacker into writing the malicious JavaScript code into some config files.

This issue affects Convict: before 6.2.4.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Nov 26, 2024
Updated Nov 27, 2024
Reserved Jan 10, 2023
CISA Vulnrichment
Updated Nov 27, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner mozilla
Published Nov 26, 2024
Updated Nov 27, 2024
Exploited since n/a
EUVD-2023-0329 GHSA-4JRM-C32X-W4JF