Description
body-parser-xml is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Remediation
References
https://github.com/fiznool/body-parser-xml/commit/d46ca622560f7c9a033cd9321c61e92558150d63
https://huntr.dev/bounties/1-other-fiznool/body-parser-xml
Related Vulnerabilities
CVE-2018-20595 Vulnerability in maven package org.hswebframework.web:hsweb-system-oauth2-client-web
CVE-2019-14862 Vulnerability in maven package org.webjars.bower:knockout
CVE-2021-23438 Vulnerability in npm package mpath
CVE-2021-44585 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core