Description
vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts.
Remediation
References
https://cwe.mitre.org/data/definitions/1321.html
https://github.com/Tencent/vConsole/issues/616
Related Vulnerabilities
CVE-2018-1000632 Vulnerability in maven package org.dom4j:dom4j
CVE-2022-35980 Vulnerability in maven package org.opensearch.plugin:opensearch-security
CVE-2023-29211 Vulnerability in maven package org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki
CVE-2022-36437 Vulnerability in maven package com.hazelcast.jet:hazelcast-jet-enterprise
CVE-2022-23620 Vulnerability in maven package org.xwiki.platform:xwiki-platform-skin-skinx