Description
Prototype pollution vulnerability via .parse() in Plist before v3.0.4 allows attackers to cause a Denial of Service (DoS) and may lead to remote code execution.
Remediation
References
https://github.com/TooTallNate/plist.js/issues/114
Related Vulnerabilities
CVE-2022-38900 Vulnerability in maven package org.webjars.npm:decode-uri-component
CVE-2020-15228 Vulnerability in npm package @actions/core
CVE-2021-39151 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2017-16222 Vulnerability in npm package elding
CVE-2022-38900 Vulnerability in npm package decode-uri-component