CVE-2022-37614

CRITICAL

Mockery - Prototype Pollution

Title source: rule
STIX 2.1

Description

Prototype pollution vulnerability in function enable in mockery.js in mfncooper mockery commit 822f0566fd6d72af8c943ae5ca2aa92e516aa2cf via the key variable in mockery.js.

Scores

CVSS v3 9.8
EPSS 0.0022
EPSS Percentile 44.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-1321
Status published
Products (2)
mockery_project/mockery 2.1.0
npm/mockery 0npm
Published Oct 12, 2022
Tracked Since Feb 18, 2026