GHSA-9pgh-qqpf-7wqj

Suggest an improvement
Source
https://github.com/advisories/GHSA-9pgh-qqpf-7wqj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/10/GHSA-9pgh-qqpf-7wqj/GHSA-9pgh-qqpf-7wqj.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-9pgh-qqpf-7wqj
Aliases
Withdrawn
2022-11-08T19:35:06Z
Published
2022-10-11T20:42:57Z
Modified
2023-11-01T05:17:51.391104Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Withdrawn: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in @xmldom/xmldom and xmldom
Details

Withdrawn

This advisory has been withdrawn because the maintainers of @xmldom/xmldom and multiple third parties disputed the validity of the issue. Attempts to create or replicate a proof of concept have been unsuccessful.

Original Description

Impact

A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package.

Patches

Update to @xmldom/xmldom@~0.7.6, @xmldom/xmldom@~0.8.3 (dist-tag latest) or @xmldom/xmldom@>=0.9.0-beta.2 (dist-tag next).

Workarounds

None

References

https://github.com/xmldom/xmldom/pull/437

For more information

If you have any questions or comments about this advisory: * Email us at security@xmldom.org * Add information to https://github.com/xmldom/xmldom/issues/436

Database specific
{
    "nvd_published_at": "2022-10-11T05:15:00Z",
    "github_reviewed_at": "2022-10-11T20:42:57Z",
    "severity": "CRITICAL",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-1321"
    ]
}
References

Affected packages

npm / @xmldom/xmldom

Package

Name
@xmldom/xmldom
View open source insights on deps.dev
Purl
pkg:npm/%40xmldom/xmldom

Affected ranges

Type
SEMVER
Events
Introduced
0.8.0
Fixed
0.8.3

npm / xmldom

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
0.6.0

npm / @xmldom/xmldom

Package

Name
@xmldom/xmldom
View open source insights on deps.dev
Purl
pkg:npm/%40xmldom/xmldom

Affected ranges

Type
SEMVER
Events
Introduced
0.9.0-beta.1
Fixed
0.9.0-beta.2

Affected versions

0.*

0.9.0-beta.1

npm / @xmldom/xmldom

Package

Name
@xmldom/xmldom
View open source insights on deps.dev
Purl
pkg:npm/%40xmldom/xmldom

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.7.6