Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-37616

Опубликовано: 11 окт. 2022
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third parties takes the position that "A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted."

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:xmldom_project:xmldom:*:*:*:*:*:node.js:*:*
Версия до 0.6.0 (включая)
cpe:2.3:a:xmldom_project:xmldom:*:*:*:*:*:node.js:*:*
Версия от 0.7.0 (включая) до 0.7.6 (исключая)
cpe:2.3:a:xmldom_project:xmldom:*:*:*:*:*:node.js:*:*
Версия от 0.8.0 (включая) до 0.8.3 (исключая)
cpe:2.3:a:xmldom_project:xmldom:0.9.0:beta1:*:*:*:node.js:*:*
Конфигурация 2
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 80%
0.0141
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-1321

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third parties takes the position that "A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted."

CVSS3: 9.8
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 9.8
debian
больше 3 лет назад

A prototype pollution vulnerability exists in the function copy in dom ...

CVSS3: 9.8
github
больше 3 лет назад

Withdrawn: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in @xmldom/xmldom and xmldom

EPSS

Процентиль: 80%
0.0141
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-1321