Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-37616

Опубликовано: 11 окт. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 9.8

Описание

A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third parties takes the position that "A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted."

РелизСтатусПримечание
bionic

DNE

devel

not-affected

0.8.6-1
esm-apps/focal

released

0.1.27+ds-1+deb10u2build0.20.04.1
esm-apps/jammy

released

0.7.5-1ubuntu0.22.04.1
focal

released

0.1.27+ds-1+deb10u2build0.20.04.1
jammy

released

0.7.5-1ubuntu0.22.04.1
kinetic

released

0.7.5-1ubuntu0.22.10.1
lunar

not-affected

0.8.6-1
trusty

DNE

upstream

released

0.8.3

Показывать по

EPSS

Процентиль: 74%
0.01606
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third parties takes the position that "A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted."

CVSS3: 9.8
msrc
6 месяцев назад

A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however some third parties takes the position that "A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted."

CVSS3: 9.8
debian
почти 4 года назад

A prototype pollution vulnerability exists in the function copy in dom ...

CVSS3: 9.8
github
почти 4 года назад

Withdrawn: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in @xmldom/xmldom and xmldom

EPSS

Процентиль: 74%
0.01606
Низкий

9.8 Critical

CVSS3