CVE-2022-37616
11.10.2022, 05:15
A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third parties takes the position that "A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted."
Vendor | Product | Version |
---|---|---|
xmldom_project | xmldom | 𝑥 ≤ 0.6.0 |
xmldom_project | xmldom | 0.7.0 ≤ 𝑥 < 0.7.6 |
xmldom_project | xmldom | 0.8.0 ≤ 𝑥 < 0.8.3 |
xmldom_project | xmldom | 0.9.0:beta1 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References