Description
body-parser-xml is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Remediation
References
https://github.com/fiznool/body-parser-xml/commit/d46ca622560f7c9a033cd9321c61e92558150d63
https://huntr.dev/bounties/1-other-fiznool/body-parser-xml
Related Vulnerabilities
CVE-2022-21186 Vulnerability in npm package @acrontum/filesystem-template
CVE-2020-15256 Vulnerability in maven package org.webjars.npm:object-path
CVE-2022-25876 Vulnerability in npm package link-preview-js
CVE-2020-35213 Vulnerability in maven package io.atomix:atomix
CVE-2022-43424 Vulnerability in maven package com.compuware.jenkins:compuware-xpediter-code-coverage