PT-2022-24028 · Npm+2 · @Xmldom/Xmldom+2

Secdevlpr26

·

Published

2022-10-11

·

Updated

2023-05-24

·

CVE-2022-37616

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions @xmldom/xmldom versions prior to 0.8.3
Description A prototype pollution vulnerability exists in the function copy in dom.js via the p variable. This issue is disputed by the vendor and some third parties, with attempts to create a proof of concept being unsuccessful.
Recommendations Update to @xmldom/xmldom@~0.7.6, @xmldom/xmldom@~0.8.3, or @xmldom/xmldom@>=0.9.0-beta.2 to resolve the issue.

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

AZL-38290
CVE-2022-37616
DLA-3154-1
GHSA-9PGH-QQPF-7WQJ
USN-6102-1

Affected Products

@Xmldom/Xmldom
Linuxmint
Ubuntu