Prototype pollution in xmldom - CVE-2022-37616

 

Prototype pollution in xmldom - CVE-2022-37616

Published: June 16, 2023


Vulnerability identifier: #VU77487
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-37616
CWE-ID: CWE-1321
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary JavaScript code.

The vulnerability exists in the function copy in dom.js in the xmldom package for Node.js via the p variable. A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in information disclosure or data manipulation.


Affected software

xmldom
Cloud Pak for Security (CP4S)
Ubuntu
node-xmldom (Ubuntu package)
IBM Cloud Pak for Watson AIOps
App Connect Enterprise Certified Container
Automation Assets in IBM Cloud Pak for Integration (CP4I)

How to mitigate CVE-2022-37616

Install update from vendor's website.

xmldom - update to 0.8.3
Cloud Pak for Security (CP4S) - update to 1.10.7.0
node-xmldom (Ubuntu package) - addressed in versions 0.1.27+ds-1+deb10u2build0.20.04.1, 0.7.5-1ubuntu0.22.04.1, 0.7.5-1ubuntu0.22.10.1
IBM Cloud Pak for Watson AIOps - update to 3.6.0
App Connect Enterprise Certified Container - addressed in versions 5.0.2, 6.1.0
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-4

External References

Related Security Bulletins