9.8
CVSSv3

CVE-2022-37616

Published: 11/10/2022 Updated: 10/02/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package prior to 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third parties takes the position that "A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xmldom project xmldom 0.9.0

xmldom project xmldom

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #1021618 node-xmldom: CVE-2022-37616 Package: src:node-xmldom; Maintainer for src:node-xmldom is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 11 Oct 2022 20:45:01 UTC Severity: important Tags: se ...

Github Repositories

Tolam Markets UI Setup Copy env-example to env before running the app Smart Contract ID used should match what's used for Microservices and may be generated using the NPM scripts provided in the Smart Contract repository Environment configuration With the env file in place, configure it based on desired runtime settings: API Root URL Point to a running version of Mic