Description
body-parser-xml is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Remediation
References
https://github.com/fiznool/body-parser-xml/commit/d46ca622560f7c9a033cd9321c61e92558150d63
https://huntr.dev/bounties/1-other-fiznool/body-parser-xml
Related Vulnerabilities
CVE-2011-2092 Vulnerability in maven package com.adobe.blazeds:blazeds-core
CVE-2021-41167 Vulnerability in npm package modern-async
CVE-2020-27224 Vulnerability in npm package @theia/preview
CVE-2022-43441 Vulnerability in npm package sqlite3
CVE-2022-29249 Vulnerability in maven package io.github.javaezlib:javaez