📦 Convict

by Mozilla

🔍 What is Convict?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-0163

HIGH CVSS 8.4 Nov 26, 2024

This CVE describes a Prototype Pollution vulnerability in Mozilla Convict, a Node.js configuration management library. Attackers can inject or override object attributes, potentially causing crashes o...

CVE-2022-21190

HIGH CVSS 7.5 May 13, 2022

CVE-2022-21190 is a prototype pollution vulnerability in the convict configuration management library for Node.js that allows attackers to modify object prototypes by bypassing the fix for CVE-2022-22...

CVE-2022-22143

HIGH CVSS 7.5 May 1, 2022

CVE-2022-22143 is a prototype pollution vulnerability in the convict configuration management library for Node.js. It allows attackers to modify object prototypes, potentially leading to denial of ser...