xml2js version 0.4.23 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the __proto__ property to be edited.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Fluid Attacks

Published: 2023-04-05T00:00:00

Updated: 2024-03-14T21:06:01.826215

Reserved: 2023-02-15T00:00:00


Link: CVE-2023-0842

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-04-05T20:15:07.493

Modified: 2024-03-14T21:15:50.517


Link: CVE-2023-0842

JSON object: View

cve-icon Redhat Information

No data.

CWE