CVE-2022-21824
published 2022-02-24CVE-2022-21824: Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while…
PriorityP355high8.2CVSS 3.1
AVNACLPRNUINSUCNILAH
EPSS
21.51%
97.3th percentile
Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first parameter, which could be "__proto__". The prototype pollution has very limited control, in that it only allows an empty string to be assigned to numerical keys of the object prototype.Node.js >= 12.22.9, >= 14.18.3, >= 16.13.2, and >= 17.3.1 use a null protoype for the object these properties are being assigned to.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | nodejs | < nodejs 12.22.9~dfsg-1 (bookworm) | nodejs 12.22.9~dfsg-1 (bookworm) |
| msrc | cbl2_nodejs_16.14.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_nodejs_14.18.3-1_on_cbl_mariner_1.0 | — | — |
| nodejs | node | >= 10.0 < 10.* | 10.* |
| nodejs | node | >= 11.0 < 11.* | 11.* |
| nodejs | node | >= 12.0 < 12.22.9 | 12.22.9 |
| nodejs | node | >= 13.0 < 13.* | 13.* |
| nodejs | node | >= 14.0 < 14.18.3 | 14.18.3 |
| nodejs | node | >= 15.0 < 15.* | 15.* |
| nodejs | node | >= 16.0 < 16.13.2 | 16.13.2 |
| nodejs | node | >= 17.0 < 17.3.1 | 17.3.1 |
| nodejs | node | >= 4.0 < 4.* | 4.* |
| nodejs | node | >= 5.0 < 5.* | 5.* |
| nodejs | node | >= 6.0 < 6.* | 6.* |
| nodejs | node | >= 7.0 < 7.* | 7.* |
| nodejs | node | >= 8.0 < 8.* | 8.* |
| nodejs | node | >= 9.0 < 9.* | 9.* |
| nodejs | node.js | >= 12.0.0 < 12.22.9 | 12.22.9 |
| nodejs | node.js | >= 14.0.0 < 14.18.3 | 14.18.3 |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv8.2HIGH
vendor_debian8.2HIGH
vendor_msrc8.2HIGH
vendor_oracle8.2HIGH
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Node.js Object Prototype console.table properties code injection (EUVD-2022-26983)
vuldb·2026-04-28·CVSS 8.2
CVE-2022-21824 [HIGH] Node.js Object Prototype console.table properties code injection (EUVD-2022-26983)
A vulnerability marked as critical has been reported in Node.js. The affected element is the function console.table of the component Object Prototype Handler. This manipulation of the argument properties causes code injection.
This vulnerability is handled as CVE-2022-21824. The attack can only be done within the local network. There is not any exploit available.
It is suggested to upgrade the affected component.
GHSA
GHSA-39wv-qjgj-4jxg: Due to the formatting logic of the "console
ghsa_unreviewed·2022-02-25
CVE-2022-21824 [HIGH] CWE-1321 GHSA-39wv-qjgj-4jxg: Due to the formatting logic of the "console
Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first parameter, which could be "__proto__". The prototype pollution has very limited control, in that it only allows an empty string to be assigned to numerical keys of the object prototype.Node.js >= 12.22.9, >= 14.18.3, >= 16.13.2, and >= 17.3.1 use a null protoype for the object these properties are being assigned to.
OSV
CVE-2022-21824: Due to the formatting logic of the "console
osv·2022-02-24·CVSS 8.2
CVE-2022-21824 [HIGH] CVE-2022-21824: Due to the formatting logic of the "console
Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first parameter, which could be "__proto__". The prototype pollution has very limited control, in that it only allows an empty string to be assigned to numerical keys of the object prototype.Node.js >= 12.22.9, >= 14.18.3, >= 16.13.2, and >= 17.3.1 use a null protoype for the object these properties are being assigned to.
Oracle
Oracle Oracle JD Edwards Risk Matrix: E1 Dev Platform Tech - Cloud Manager (Node.js) — CVE-2022-21824
vendor_oracle·2023-04-15·CVSS 8.2
CVE-2022-21824 [HIGH] Oracle Oracle JD Edwards Risk Matrix: E1 Dev Platform Tech - Cloud Manager (Node.js) — CVE-2022-21824
Oracle Oracle JD Edwards Risk Matrix: E1 Dev Platform Tech - Cloud Manager (Node.js) vulnerability
CVE: CVE-2022-21824
CVSS: 8.2
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Policy (MySQL) — CVE-2022-21824
vendor_oracle·2023-01-15·CVSS 8.2
CVE-2022-21824 [HIGH] Oracle Oracle Communications Risk Matrix: Policy (MySQL) — CVE-2022-21824
Oracle Oracle Communications Risk Matrix: Policy (MySQL) vulnerability
CVE: CVE-2022-21824
CVSS: 8.2
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Oracle
Oracle Oracle MySQL Risk Matrix: Cluster: General (Node.js) — CVE-2022-21824
vendor_oracle·2022-07-15·CVSS 8.2
CVE-2022-21824 [HIGH] Oracle Oracle MySQL Risk Matrix: Cluster: General (Node.js) — CVE-2022-21824
Oracle Oracle MySQL Risk Matrix: Cluster: General (Node.js) vulnerability
CVE: CVE-2022-21824
CVSS: 8.2
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Microsoft
Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with
vendor_msrc·2022-02-08·CVSS 8.2
CVE-2022-21824 [HIGH] CWE-1321 Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with
Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first parameter which could be "__proto__". The prototype pollution has very limited control in that it only allows an empty string to be assigned to numerical keys of the object prototype.Node.js >= 12.22.9 >= 14.18.3 >= 16.13.2 and >= 17.3.1 use a null protoype for the object these properties are being assigned to.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to
Red Hat
nodejs: Prototype pollution via console.table properties
vendor_redhat·2022-01-10·CVSS 8.2
CVE-2022-21824 [HIGH] CWE-915 nodejs: Prototype pollution via console.table properties
nodejs: Prototype pollution via console.table properties
Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first parameter, which could be "__proto__". The prototype pollution has very limited control, in that it only allows an empty string to be assigned to numerical keys of the object prototype.Node.js >= 12.22.9, >= 14.18.3, >= 16.13.2, and >= 17.3.1 use a null protoype for the object these properties are being assigned to.
Statement: Red Hat Quay from version 3.4 consumes nodejs from RHEL, so security tracking is provided by the container health index on the customer portal [1]. Additionally there is no imp
Debian
CVE-2022-21824: nodejs - Due to the formatting logic of the "console.table()" function it was not safe to...
vendor_debian·2022·CVSS 8.2
CVE-2022-21824 [HIGH] CVE-2022-21824: nodejs - Due to the formatting logic of the "console.table()" function it was not safe to...
Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first parameter, which could be "__proto__". The prototype pollution has very limited control, in that it only allows an empty string to be assigned to numerical keys of the object prototype.Node.js >= 12.22.9, >= 14.18.3, >= 16.13.2, and >= 17.3.1 use a null protoype for the object these properties are being assigned to.
Scope: local
bookworm: resolved (fixed in 12.22.9~dfsg-1)
bullseye: resolved (fixed in 12.22.12~dfsg-1~deb11u1)
forky: resolved (fixed in 12.22.9~dfsg-1)
sid: resolved (fixed in 12.22.9~dfsg-1)
trixie: resolved (fixed in 12.22.9~dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://hackerone.com/reports/1431042https://lists.debian.org/debian-lts-announce/2022/10/msg00006.htmlhttps://nodejs.org/en/blog/vulnerability/jan-2022-security-releases/https://security.netapp.com/advisory/ntap-20220325-0007/https://security.netapp.com/advisory/ntap-20220729-0004/https://www.debian.org/security/2022/dsa-5170https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://hackerone.com/reports/1431042https://lists.debian.org/debian-lts-announce/2022/10/msg00006.htmlhttps://nodejs.org/en/blog/vulnerability/jan-2022-security-releases/https://security.netapp.com/advisory/ntap-20220325-0007/https://security.netapp.com/advisory/ntap-20220729-0004/https://www.debian.org/security/2022/dsa-5170https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2022-02-24
Published