Description
body-parser-xml is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Remediation
References
https://github.com/fiznool/body-parser-xml/commit/d46ca622560f7c9a033cd9321c61e92558150d63
https://huntr.dev/bounties/1-other-fiznool/body-parser-xml
Related Vulnerabilities
CVE-2020-13943 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2021-44228 Vulnerability in maven package org.apache.logging.log4j:log4j-core
CVE-2021-23442 Vulnerability in npm package @cookiex/deep
CVE-2022-28220 Vulnerability in maven package org.apache.james.protocols:protocols-netty
CVE-2021-21293 Vulnerability in maven package org.http4s:blaze-core_2.11