PT-2022-24029 · Thlorenz · Browserify-Shim

Secdevlpr26

·

Published

2022-10-11

·

Updated

2022-10-13

·

CVE-2022-37617

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions thlorenz browserify-shim version 3.8.15
Description The issue is related to a prototype pollution vulnerability in the resolveShims function within the resolve-shims.js file of thlorenz browserify-shim. This vulnerability is exploited via the k variable in resolve-shims.js.
Recommendations For thlorenz browserify-shim version 3.8.15, consider disabling the resolveShims function as a temporary workaround until a patch is available. Restrict access to the resolve-shims.js file to minimize the risk of exploitation. Avoid using the k variable in the affected function until the issue is resolved.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2022-37617
GHSA-866W-WM4H-95C6

Affected Products

Browserify-Shim