Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-37616
HistoryOct 11, 2022 - 12:00 a.m.

CVE-2022-37616

2022-10-1100:00:00
ubuntu.com
ubuntu.com
25
vulnerability
xmldom package
node.js

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

69.2%

A prototype pollution vulnerability exists in the function copy in dom.js
in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for
Node.js via the p variable. NOTE: the vendor states “we are in the process
of marking this report as invalid”; however, some third parties takes the
position that “A prototype injection/Prototype pollution is not just when
global objects are polluted with recursive merge or deep cloning but also
when a target object is polluted.”

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchnode-xmldom< 0.1.27+ds-1+deb10u2build0.20.04.1UNKNOWN
ubuntu22.04noarchnode-xmldom< 0.7.5-1ubuntu0.22.04.1UNKNOWN
ubuntu22.10noarchnode-xmldom< 0.7.5-1ubuntu0.22.10.1UNKNOWN

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

69.2%