CVE-2022-37616
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third parties takes the position that "A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted."
Se presenta una vulnerabilidad de contaminación de prototipos en la función copy en el archivo dom.js en el paquete xmldom (publicado como @xmldom/xmldom) versiones anteriores a 0.8.3 para Node.js por medio de la variable p. NOTA: el proveedor afirma que "estamos en proceso de marcar este informe como no válido"
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-08-08 CVE Reserved
- 2022-10-11 CVE Published
- 2024-06-01 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://users.encs.concordia.ca/~mmannan/publications/JS-vulnerability-aisaccs2022.pdf | Technical Description | |
https://dl.acm.org/doi/abs/10.1145/3488932.3497769 | Technical Description | |
https://dl.acm.org/doi/pdf/10.1145/3488932.3497769 | Third Party Advisory | |
https://github.com/xmldom/xmldom/issues/436#issuecomment-1319412826 | Issue Tracking | |
https://github.com/xmldom/xmldom/issues/436#issuecomment-1327776560 | Issue Tracking | |
https://github.com/xmldom/xmldom/security/advisories/GHSA-9pgh-qqpf-7wqj | Third Party Advisory | |
https://lists.debian.org/debian-lts-announce/2022/10/msg00023.html | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Xmldom Project Search vendor "Xmldom Project" | Xmldom Search vendor "Xmldom Project" for product "Xmldom" | <= 0.6.0 Search vendor "Xmldom Project" for product "Xmldom" and version " <= 0.6.0" | node.js |
Affected
| ||||||
Xmldom Project Search vendor "Xmldom Project" | Xmldom Search vendor "Xmldom Project" for product "Xmldom" | >= 0.7.0 < 0.7.6 Search vendor "Xmldom Project" for product "Xmldom" and version " >= 0.7.0 < 0.7.6" | node.js |
Affected
| ||||||
Xmldom Project Search vendor "Xmldom Project" | Xmldom Search vendor "Xmldom Project" for product "Xmldom" | >= 0.8.0 < 0.8.3 Search vendor "Xmldom Project" for product "Xmldom" and version " >= 0.8.0 < 0.8.3" | node.js |
Affected
| ||||||
Xmldom Project Search vendor "Xmldom Project" | Xmldom Search vendor "Xmldom Project" for product "Xmldom" | 0.9.0 Search vendor "Xmldom Project" for product "Xmldom" and version "0.9.0" | beta1, node.js |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
|