Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9pgh-qqpf-7wqj

Опубликовано: 11 окт. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Withdrawn: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in @xmldom/xmldom and xmldom

Withdrawn

This advisory has been withdrawn because the maintainers of @xmldom/xmldom and multiple third parties disputed the validity of the issue. Attempts to create or replicate a proof of concept have been unsuccessful.

Original Description

Impact

A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package.

Patches

Update to @xmldom/xmldom@~0.7.6, @xmldom/xmldom@~0.8.3 (dist-tag latest) or @xmldom/xmldom@>=0.9.0-beta.2 (dist-tag next).

Workarounds

None

References

https://github.com/xmldom/xmldom/pull/437

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

@xmldom/xmldom

npm
Затронутые версииВерсия исправления

>= 0.8.0, < 0.8.3

0.8.3

Наименование

xmldom

npm
Затронутые версииВерсия исправления

<= 0.6.0

Отсутствует

Наименование

@xmldom/xmldom

npm
Затронутые версииВерсия исправления

= 0.9.0-beta.1

0.9.0-beta.2

Наименование

@xmldom/xmldom

npm
Затронутые версииВерсия исправления

< 0.7.6

0.7.6

EPSS

Процентиль: 80%
0.0141
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-1321

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third parties takes the position that "A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted."

CVSS3: 9.8
nvd
больше 3 лет назад

A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third parties takes the position that "A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted."

CVSS3: 9.8
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 9.8
debian
больше 3 лет назад

A prototype pollution vulnerability exists in the function copy in dom ...

EPSS

Процентиль: 80%
0.0141
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-1321