Skip to content
COOEY

EXPOSURES › CVE-2022-37257

CVE-2022-37257

CRITICAL
DETAIL
SourceNVD · cve Published2022-09-15 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-37257 ↗
⚡ RCE SHAME 50/100 rce

Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js.

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.