PT-2022-24925 · Winter · Winter

Lowbennothommopublished

·

Published

2022-10-26

·

Updated

2022-10-28

·

CVE-2022-39357

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Winter versions 1.1.8 through 1.2.0
Description The Snowboard framework in Winter is vulnerable to prototype pollution in the main Snowboard class as well as its plugin loader. This issue has been patched in versions 1.1.10 and 1.2.1. As a workaround, one may avoid this issue by following some common security practices for JavaScript, including implementing a content security policy and auditing scripts.
Recommendations For versions 1.1.8 through 1.1.9, update to version 1.1.10 to resolve the issue. For version 1.2.0, update to version 1.2.1 to resolve the issue. As a temporary workaround, consider implementing a content security policy and auditing scripts to minimize the risk of exploitation.

Exploit

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-39357
GHSA-3FH5-Q6FG-W28Q

Affected Products

Winter