convict
npm3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting convictpage 1 of 1
- CVE-2022-21190HIGHCVSS 7.5EG 7.5✓ Fixed in 6.2.32022-05-13
This affects the package convict before 6.2.3. This is a bypass of [CVE-2022-22143](https://security.snyk.io/vuln/SNYK-JS-CONVICT-2340604). The [fix](https://github.com/mozilla/node-convict/commit/3b86be087d8f14681a9c889d45da7fe3ad9cd880) …
- CVE-2022-22143HIGHCVSS 7.5EG 7.5✓ Fixed in 6.2.32022-05-01
The package convict before 6.2.2 are vulnerable to Prototype Pollution via the convict function due to missing validation of parentKey. **Note:** This vulnerability derives from an incomplete fix of another [vulnerability](https://security…
- CVE-2023-0163HIGHCVSS 8.4EG 8.4✓ Fixed in 6.2.42024-11-26
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Mozilla Convict. This allows an attacker to inject attributes that are used in other components, or to override existing attributes…
Check whether convict is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for convict CVEs against the assets you own.
Start Free Scan →