CVE-2022-37616

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/10/2022
Last modified:
10/02/2023

Description

A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third parties takes the position that "A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xmldom_project:xmldom:*:*:*:*:*:node.js:*:* 0.6.0 (including)
cpe:2.3:a:xmldom_project:xmldom:*:*:*:*:*:node.js:*:* 0.7.0 (including) 0.7.6 (excluding)
cpe:2.3:a:xmldom_project:xmldom:*:*:*:*:*:node.js:*:* 0.8.0 (including) 0.8.3 (excluding)
cpe:2.3:a:xmldom_project:xmldom:0.9.0:beta1:*:*:*:node.js:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*