xml2js version 0.4.23 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the __proto__ property to be edited.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Feb 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2025-02-13T19:13:03.902Z
Reserved: 2023-02-15T00:00:00.000Z
Link: CVE-2023-0842

Updated: 2024-08-02T05:24:34.583Z

Status : Modified
Published: 2023-04-05T20:15:07.493
Modified: 2025-02-13T20:15:47.193
Link: CVE-2023-0842
