PT-2022-24032 · Unknown · Browserify-Shim

Secdevlpr26

·

Published

2022-10-28

·

Updated

2022-11-03

·

CVE-2022-37621

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions browserify-shim version 3.8.15
Description The issue is related to a prototype pollution vulnerability in the resolveShims function, located in resolve-shims.js. This vulnerability is exploitable via the fullPath variable in resolve-shims.js.
Recommendations For browserify-shim version 3.8.15, consider updating to a newer version that contains a fix for this issue, if available. As a temporary workaround, consider restricting access to the resolveShims function in resolve-shims.js to minimize the risk of exploitation. Avoid using the fullPath variable in the affected resolve-shims.js until the issue is resolved.

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2022-37621
GHSA-R737-347M-WQC7

Affected Products

Browserify-Shim