CVE-2022-39357
published 2022-10-26CVE-2022-39357: Winter is a free, open-source content management system based on the Laravel PHP framework. The Snowboard framework in versions 1.1.8, 1.1.9, and 1.2.0 is…
PriorityP348critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.03%
59.3th percentile
Winter is a free, open-source content management system based on the Laravel PHP framework. The Snowboard framework in versions 1.1.8, 1.1.9, and 1.2.0 is vulnerable to prototype pollution in the main Snowboard class as well as its plugin loader. The 1.0 branch of Winter is not affected, as it does not contain the Snowboard framework. This issue has been patched in v1.1.10 and v1.2.1. As a workaround, one may avoid this issue by following some common security practices for JavaScript, including implementing a content security policy and auditing scripts.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wintercms | winter | — | — |
| wintercms | winter | — | — |
| wintercms | winter | — | — |
| wintercms | winter | — | — |
| wintercms | winter | — | — |
| wintercms | winter | >= 1.1.8 < 1.1.10 | 1.1.10 |
| wintercms | winter | >= 1.2.0 < 1.2.1 | 1.2.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Prototype pollution in Snowboard framework
ghsa·2022-10-27
CVE-2022-39357 [HIGH] CWE-1321 Prototype pollution in Snowboard framework
Prototype pollution in Snowboard framework
### Impact
The Snowboard framework in affected versions is vulnerable to prototype pollution in the main Snowboard class as well as its plugin loader.
### Patches
This issue has been patched in https://github.com/wintercms/winter/commit/2a13faf99972e84c9661258f16c4750fa99d29a1 (for 1.2) and https://github.com/wintercms/winter/commit/bce4b59584abf961e9400af3d7a4fd7638e26c7f (for 1.1) and is available with Winter v1.1.10 and v1.2.1.
### Workarounds
If you have not yet upgraded, or are using the 1.1 branch of Winter (1.1.8 or above), you can avoid this issue by following some common security practices for JavaScript, including implementing a [content security policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP) and auditing your scrip
OSV
Prototype pollution in Snowboard framework
osv·2022-10-27
CVE-2022-39357 [HIGH] Prototype pollution in Snowboard framework
Prototype pollution in Snowboard framework
### Impact
The Snowboard framework in affected versions is vulnerable to prototype pollution in the main Snowboard class as well as its plugin loader.
### Patches
This issue has been patched in https://github.com/wintercms/winter/commit/2a13faf99972e84c9661258f16c4750fa99d29a1 (for 1.2) and https://github.com/wintercms/winter/commit/bce4b59584abf961e9400af3d7a4fd7638e26c7f (for 1.1) and is available with Winter v1.1.10 and v1.2.1.
### Workarounds
If you have not yet upgraded, or are using the 1.1 branch of Winter (1.1.8 or above), you can avoid this issue by following some common security practices for JavaScript, including implementing a [content security policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP) and auditing your scrip
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/wintercms/winter/commit/2a13faf99972e84c9661258f16c4750fa99d29a1https://github.com/wintercms/winter/commit/bce4b59584abf961e9400af3d7a4fd7638e26c7fhttps://github.com/wintercms/winter/releases/tag/v1.1.10https://github.com/wintercms/winter/releases/tag/v1.2.1https://github.com/wintercms/winter/security/advisories/GHSA-3fh5-q6fg-w28qhttps://github.com/wintercms/winter/commit/2a13faf99972e84c9661258f16c4750fa99d29a1https://github.com/wintercms/winter/commit/bce4b59584abf961e9400af3d7a4fd7638e26c7fhttps://github.com/wintercms/winter/releases/tag/v1.1.10https://github.com/wintercms/winter/releases/tag/v1.2.1https://github.com/wintercms/winter/security/advisories/GHSA-3fh5-q6fg-w28q
2022-10-26
Published