Description
body-parser-xml is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Remediation
References
https://github.com/fiznool/body-parser-xml/commit/d46ca622560f7c9a033cd9321c61e92558150d63
https://huntr.dev/bounties/1-other-fiznool/body-parser-xml
Related Vulnerabilities
CVE-2022-25858 Vulnerability in maven package org.webjars.npm:terser
CVE-2022-45693 Vulnerability in maven package org.codehaus.jettison:jettison
CVE-2020-8131 Vulnerability in npm package yarn
CVE-2011-2526 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2023-45137 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates