// For flags

CVE-2022-37616

 

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third parties takes the position that "A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted."

Se presenta una vulnerabilidad de contaminación de prototipos en la función copy en el archivo dom.js en el paquete xmldom (publicado como @xmldom/xmldom) versiones anteriores a 0.8.3 para Node.js por medio de la variable p. NOTA: el proveedor afirma que "estamos en proceso de marcar este informe como no válido"

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-08-08 CVE Reserved
  • 2022-10-11 CVE Published
  • 2024-06-01 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Xmldom Project
Search vendor "Xmldom Project"
Xmldom
Search vendor "Xmldom Project" for product "Xmldom"
<= 0.6.0
Search vendor "Xmldom Project" for product "Xmldom" and version " <= 0.6.0"
node.js
Affected
Xmldom Project
Search vendor "Xmldom Project"
Xmldom
Search vendor "Xmldom Project" for product "Xmldom"
>= 0.7.0 < 0.7.6
Search vendor "Xmldom Project" for product "Xmldom" and version " >= 0.7.0 < 0.7.6"
node.js
Affected
Xmldom Project
Search vendor "Xmldom Project"
Xmldom
Search vendor "Xmldom Project" for product "Xmldom"
>= 0.8.0 < 0.8.3
Search vendor "Xmldom Project" for product "Xmldom" and version " >= 0.8.0 < 0.8.3"
node.js
Affected
Xmldom Project
Search vendor "Xmldom Project"
Xmldom
Search vendor "Xmldom Project" for product "Xmldom"
0.9.0
Search vendor "Xmldom Project" for product "Xmldom" and version "0.9.0"
beta1, node.js
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
10.0
Search vendor "Debian" for product "Debian Linux" and version "10.0"
-
Affected