cbcvebase.
CVE-2022-37616
published 2022-10-11

CVE-2022-37616: A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the…

PriorityP348critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.54%
72.0th percentile
A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third parties takes the position that "A prototype injection/Prototype pollution is not just when global objects are polluted with recursive merge or deep cloning but also when a target object is polluted."

Affected

15 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiannode-xmldom< node-xmldom 0.8.3-1 (bookworm)node-xmldom 0.8.3-1 (bookworm)
msrcazl3_python-tensorboard_2.11.0-3_on_azure_linux_3.0
msrcazl3_python-tensorboard_2.16.2-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_python-tensorboard_2.11.0-3_on_cbl_mariner_2.0
xmldomxmldom>= 0 < 0.7.60.7.6
xmldomxmldom0 – 0.6.0
xmldomxmldom>= 0.8.0 < 0.8.30.8.3
xmldomxmldom>= 0.9.0-beta.1 < 0.9.0-beta.20.9.0-beta.2
xmldom_projectxmldom<= 0.6.0
xmldom_projectxmldom
xmldom_projectxmldom>= 0.7.0 < 0.7.60.7.6
xmldom_projectxmldom>= 0.8.0 < 0.8.30.8.3

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.