xml2js version 0.4.23 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the __proto__ property to be edited.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published: 2023-04-05T00:00:00

Updated: 2024-08-02T05:24:34.583Z

Reserved: 2023-02-15T00:00:00

Link: CVE-2023-0842

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-04-05T20:15:07.493

Modified: 2024-11-21T07:37:56.420

Link: CVE-2023-0842

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-04-05T00:00:00Z

Links: CVE-2023-0842 - Bugzilla