A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. Reference: https://github.com/xmldom/xmldom/issues/436 https://github.com/xmldom/xmldom/security/advisories/GHSA-9pgh-qqpf-7wqj
Created nodejs-xmldom tracking bugs for this issue: Affects: epel-7 [bug 2135238]
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-37616