Back to bug 2193459

Who When What Removed Added
Patrick Del Bello 2023-05-05 17:15:04 UTC CC aileenc, amctagga, bdettelb, erack, fmuellner, fzatlouk, gmalinko, gzaronik, janstey, jhorak, jkoehler, jpavlik, jrybar, jshaughn, jwendell, klember, mokumar, nbecker, nboldt, ocs-bugs, pdelbell, rcernich, scorneli, stransky, tpopela, twalsh
Patrick Del Bello 2023-05-05 17:16:48 UTC Depends On 2193466, 2193460, 2193463, 2193461, 2193464, 2193465, 2193462
Patrick Del Bello 2023-05-05 17:18:00 UTC Fixed In Version node-xml2js 0.5.0 xml2js 0.5.0
RaTasha Tillery-Smith 2023-05-08 12:44:34 UTC Doc Text A flaw was found in node-xml2js. This flaw allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the __proto__ property to be edited. A flaw was found in node-xml2js. This flaw allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, making it possible to edit the __proto__ property.
Avinash Hanwate 2023-05-15 07:06:58 UTC Depends On 2203734, 2203735
Jan Rybar 2023-05-15 11:50:57 UTC Doc Type --- If docs needed, set a value
CC jrybar
RaTasha Tillery-Smith 2023-05-15 13:50:22 UTC CC dfreiber, jburrell, rogbas, vkumar
Red Hat Bugzilla 2023-05-16 09:27:32 UTC CC mokumar
Red Hat Bugzilla 2023-07-07 08:32:41 UTC Assignee security-response-team nobody
Red Hat Bugzilla 2023-07-21 22:26:24 UTC CC jpavlik
Red Hat Bugzilla 2023-08-03 08:28:26 UTC CC ocs-bugs

Back to bug 2193459