Bug 2193459 (CVE-2023-0842)
Summary: | CVE-2023-0842 node-xml2js: xml2js is vulnerable to prototype pollution | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Patrick Del Bello <pdelbell> |
Component: | vulnerability | Assignee: | Nobody <nobody> |
Status: | NEW --- | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | aileenc, amctagga, bdettelb, chazlett, dfreiber, erack, fmuellner, fzatlouk, gmalinko, gzaronik, janstey, jburrell, jhorak, jkoehler, jshaughn, jwendell, nbecker, nboldt, pdelbell, pjindal, rcernich, rogbas, scorneli, stransky, tpopela, twalsh, vkumar |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | xml2js 0.5.0 | Doc Type: | If docs needed, set a value |
Doc Text: |
A flaw was found in node-xml2js. This flaw allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, making it possible to edit the __proto__ property.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2193460, 2193461, 2193462, 2193463, 2193464, 2193465, 2193466, 2203734, 2203735 | ||
Bug Blocks: | 2184896 |
Description
Patrick Del Bello
2023-05-05 17:14:10 UTC
Created llhttp tracking bugs for this issue: Affects: fedora-all [bug 2193461] Created mozjs68 tracking bugs for this issue: Affects: fedora-all [bug 2193462] Created mozjs78 tracking bugs for this issue: Affects: fedora-all [bug 2193463] Created php-laminas-xml2json tracking bugs for this issue: Affects: fedora-all [bug 2193464] Created phpdoc tracking bugs for this issue: Affects: fedora-all [bug 2193465] Created seamonkey tracking bugs for this issue: Affects: epel-all [bug 2193460] Affects: fedora-all [bug 2193466] |